diff --git a/.github/pull_request_template.md b/.github/pull_request_template.md new file mode 100644 index 0000000..133ce46 --- /dev/null +++ b/.github/pull_request_template.md @@ -0,0 +1,11 @@ +### What I did + + + +### How I did it + + + +### Example screenshots/gifs (suggested for frontend work) + + diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..9da51e4 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,34 @@ +name: CI + +on: + workflow_dispatch: + pull_request: # Allow building on any PR + push: + branches: + - master + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +jobs: + checkmarx: + name: ✅ Checkmarx Vulnerability Scan ✅ + runs-on: ubuntu-latest + permissions: + contents: read + pull-requests: write + statuses: write + steps: + - name: Checkout code + uses: actions/checkout@v3 + - name: Scan project + uses: Checkmarx/ast-github-action@2.0.14 + with: + base_uri: https://ast.checkmarx.net/ + cx_tenant: shifttechnologies + cx_client_id: ${{ secrets.CHECKMARX_CLIENT_ID }} + cx_client_secret: ${{ secrets.CHECKMARX_CLIENT_SECRET }} + project_name: ${{ github.repository }} + branch: ${{ github.ref }} + additional_params: --sast-incremental --scan-types sast --filter status=NEW --threshold "sast-high=18"