# Name of this GitHub Actions workflow.
name: Semgrep

on:
  # Scan changed files in PRs (diff-aware scanning):
  pull_request: {}

jobs:
  semgrep:
    # User-definable name of this GitHub Actions job:
    name: Scan code
    # If you are self-hosting, change the following `runs-on` value:
    runs-on: ubuntu-latest

    container:
      # A Docker image with Semgrep installed. Do not change this.
      image: returntocorp/semgrep

    # To skip any PR created by dependabot to avoid permission issues:
    if: (github.actor != 'dependabot[bot]')

    steps:
      # Fetch project source with GitHub Actions Checkout.
      - uses: actions/checkout@v3
      # Run the "semgrep ci" command on the command line of the docker image.
      - run: semgrep ci
        env:
          # Add the rules that Semgrep uses by setting the SEMGREP_RULES environment variable.
          SEMGREP_RULES: p/default # more at semgrep.dev/explore
          # Uncomment SEMGREP_TIMEOUT to set this job's timeout (in seconds):
          # Default timeout is 1800 seconds (30 minutes).
          # Set to 0 to disable the timeout.
          # SEMGREP_TIMEOUT: 300
