SECOND Update README.md #33
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Checkmarx One Scan | |
on: | |
push: | |
branches: | |
- master | |
- feature/187 | |
jobs: | |
dast: | |
runs-on: ubuntu-latest | |
name: DAST | |
steps: | |
- name: Checkout Code | |
uses: actions/checkout@v3 | |
- name: Create Output folder | |
run: mkdir ${{ github.workspace }}/output | |
- name: Change dir owner | |
run: sudo chown -R 1000:1000 ${{ github.workspace }} | |
# - name: copy YAML | |
# run: cp testphp.yml ${{ github.workspace }}/testphp.yaml | |
- name: PWD | |
run: pwd | |
- name: echo workspace | |
run: echo ${{ github.workspace }} | |
# - name: COPY YAML | |
# run: cp testphp.yml /github/workspace/ | |
- name: ls dirs | |
run: ls -larh ${{ github.workspace }} | |
- name: Checkmarx DAST Github Action | |
uses: Checkmarx/dast-github-action@v1.0.4 | |
env: | |
CX_APIKEY: eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJjZDBmN2QxMS00YjE0LTQ3YTUtYTlhMy1lMmI2M2YwOTUwZTAifQ.eyJpYXQiOjE2ODcyOTI2NDcsImp0aSI6IjQ5N2M5NWMxLTM5NjktNGFhOS04ZWMyLTZlMDEyNzk4NmE4ZSIsImlzcyI6Imh0dHBzOi8vaWFtLmNoZWNrbWFyeC5uZXQvYXV0aC9yZWFsbXMvY3hvbmUtc2FtaCIsImF1ZCI6Imh0dHBzOi8vaWFtLmNoZWNrbWFyeC5uZXQvYXV0aC9yZWFsbXMvY3hvbmUtc2FtaCIsInN1YiI6IjhjODRkNTgzLTgyNTAtNGJlYi04MGViLWY5YzE1N2QxYzU0MSIsInR5cCI6Ik9mZmxpbmUiLCJhenAiOiJhc3QtYXBwIiwic2Vzc2lvbl9zdGF0ZSI6IjAxMjIwMTE3LTY4MDAtNDY5ZS05MmRiLWI1MDI2YTZjZDhmOCIsInNjb3BlIjoiIG9mZmxpbmVfYWNjZXNzIiwic2lkIjoiMDEyMjAxMTctNjgwMC00NjllLTkyZGItYjUwMjZhNmNkOGY4In0.Z5kO33Y3_GWIlQFqm68dk9QXj9JGAN-A4zIUChZcxRs | |
with: | |
command: web | |
config: ${{ github.workspace }}/testphp.yml | |
environment_id: 89283d54-7933-4600-b9df-9a4807db7347 | |
fail_on: "HIGH" | |
log_level: info | |
base_url: https://ast.checkmarx.net | |
verbose: true | |
output: ${{ github.workspace }}/output | |
- name: Change dir owner back to gh user | |
if: always() | |
run: sudo chown -R 1001:1001 ${{ github.workspace }}/output | |
- uses: actions/upload-artifact@v3 | |
if: always() | |
name: Upload Logs | |
with: | |
name: report | |
path: ${{ github.workspace }}/output |