diff --git a/.github/workflows/bearer-pr.yml b/.github/workflows/bearer-pr.yml new file mode 100644 index 0000000..d2f9a6b --- /dev/null +++ b/.github/workflows/bearer-pr.yml @@ -0,0 +1,20 @@ +name: Bearer PR Check + +on: + pull_request: + types: [opened, synchronize, reopened] + +permissions: + contents: read + +jobs: + rule_check: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + + - name: Bearer + uses: bearer/bearer-action@v2 + with: + diff: true diff --git a/.github/workflows/bearer.yml b/.github/workflows/bearer.yml new file mode 100644 index 0000000..2172acb --- /dev/null +++ b/.github/workflows/bearer.yml @@ -0,0 +1,29 @@ +name: Bearer Master + +on: + push: + branches: + - master + +permissions: + contents: read + security-events: write + +jobs: + rule_check: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + + - name: Bearer + uses: bearer/bearer-action@v2 + with: + format: sarif + output: results.sarif + + - name: Upload SARIF file + if: always() + uses: github/codeql-action/upload-sarif@v2 + with: + sarif_file: results.sarif