diff --git a/.github/workflows/semgrep-analysis.yml b/.github/workflows/semgrep-analysis.yml index 5f2993737c..15094de479 100644 --- a/.github/workflows/semgrep-analysis.yml +++ b/.github/workflows/semgrep-analysis.yml @@ -44,15 +44,15 @@ jobs: # Scan code using project's configuration on https://semgrep.dev/manage - uses: returntocorp/semgrep-action@v1 with: - generateSarif: "0" + generateSarif: "1" config: >- # more at semgrep.dev/explore p/security-audit p/secrets # Upload SARIF file generated in previous step #The following lines are commented out right now pending a fix to the semgrep repo - #- name: Upload SARIF file - # uses: github/codeql-action/upload-sarif@v1 - # with: - # sarif_file: semgrep.sarif - # if: always() + - name: Upload SARIF file + uses: github/codeql-action/upload-sarif@v1 + with: + sarif_file: semgrep.sarif + if: always()