diff --git a/.github/workflows/sast-push.yaml b/.github/workflows/sast-push.yaml new file mode 100644 index 0000000..398257f --- /dev/null +++ b/.github/workflows/sast-push.yaml @@ -0,0 +1,29 @@ +name: Push SonarQube scans to SaaS + +on: + push: + branches: + - main + +env: + AK_URL: "https://cspm.accuknox.com" + AK_SAST_LABEL: "SAST" + +jobs: + scan-and-push: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v2 + - uses: accuknox/common-gh-actions/actions/sonarqube@main + with: + token: ${{ secrets.SQ_TOKEN }} + qualityGateCheck: 'false' + args: > + -Dsonar.projectKey=knoxctl-website + -Dsonar.sources=. + projectKey: knoxctl-website + pushToSaas: true + ak_url: ${{ env.AK_URL }} + ak_tok: ${{ secrets.AK_PROD_ACCUKNOXTECH_TOKEN }} + tenant_id: ${{ secrets.AK_PROD_ACCUKNOXTECH_TENANT_ID }} + label: ${{ env.AK_SAST_LABEL }} \ No newline at end of file