-
Notifications
You must be signed in to change notification settings - Fork 16
111 lines (98 loc) · 3.25 KB
/
Copy pathbasic-example.yml
File metadata and controls
111 lines (98 loc) · 3.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
# An example workflow using the NowSecure action that builds an Android application
# in the "build" phase and then runs it against NowSecure in the "scan" phase.
# This action is run each time a commit is pushed to the "main" branch.
name: NowSecure Basic Example
on:
# For a real workflow, you'd likely want to run on push to main. Example:
# push:
# branches: [main]
# pull_request:
# branches: [main]
workflow_dispatch:
jobs:
build:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v6
# TODO: Insert your actual build steps here. Example:
#
# - name: Install Java
# uses: actions/setup-java@v2
# with:
# java-version: "21"
# distribution: "adopt"
# cache: "gradle"
#
# - name: Build project
# run |
# ./gradlew clean build
- name: Upload application
uses: actions/upload-artifact@v4
with:
name: app
# TODO: Replace the following line with the path to your built artifact
path: ./test-artifacts/MASTG-DEMO-0031.apk
# Scan the Android application with NowSecure.
scan:
runs-on: ubuntu-latest
outputs:
report_id: ${{ steps.upload.outputs.report_id }}
needs: build
steps:
- name: Checkout repository
uses: actions/checkout@v6
# NOTE: The NowSecure Action leverages ripgrep
- name: Install ripgrep
run: sudo apt-get install --no-install-recommends -y ripgrep
- name: Download application
uses: actions/download-artifact@v5
with:
name: app
- id: upload
name: NowSecure upload app
# TODO: switch to the following:
# uses: nowsecure/nowsecure-action/upload-app@v5
uses: ./upload-app
with:
# TODO: Make sure you change these to your actual values
platform_token: ${{ secrets.NS_TOKEN }}
analysis_type: static
group_id: ${{ vars.NS_GROUP }}
app_file: ./MASTG-DEMO-0031.apk
# Pulls the NowSecure report, converts it to SARIF and uploads it.
process:
if: ${{ needs.scan.outputs.report_id }}
runs-on: ubuntu-latest
environment:
name: nowsecure-env
needs: scan
permissions:
# required for all workflows
security-events: write
# only required for workflows in private repositories
actions: read
contents: read
steps:
- name: Checkout repository
uses: actions/checkout@v6
- name: NowSecure download report
# TODO: switch to the following:
# uses: nowsecure/nowsecure-action/convert-sarif@v5
uses: ./convert-sarif
timeout-minutes: 60
with:
report_id: ${{ needs.scan.outputs.report_id }}
# TODO: Make sure you change these to your actual values
platform_token: ${{ secrets.NS_TOKEN }}
group_id: ${{ vars.NS_GROUP }}
minimum_score: ${{ vars.MIN_SCORE }}
- name: Upload SARIF file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: NowSecure.sarif
- name: Upload SARIF to artifacts
uses: actions/upload-artifact@v4
with:
name: NowSecure.sarif
path: ./NowSecure.sarif