Skip to content

Mobbeitan patch 1

Mobbeitan patch 1 #208

Workflow file for this run

name: "Mobb/Snyk"
on:
pull_request:
branches: ["main"]
jobs:
scan-and-fix:
name: Scan with Snyk and fix with Mobb
runs-on: 'ubuntu-latest'
timeout-minutes: 360
permissions:
pull-requests: write
statuses: write
steps:
- name: Checkout repository
uses: actions/checkout@v3
- name: Run Snyk SAST scan
run:
npx snyk auth ${{ secrets.SNYK_API_KEY }} && npx snyk code test --sarif-file-output=/home/runner/report.json ./
shell: bash -l {0}
- name: Run Mobb on the findings and get fixes
if: always()
uses: mobb-dev/action/[email protected]
with:
report-file: "/home/runner/report.json"
api-key: ${{ secrets.MOBB_API_TOKEN }}
github-token: ${{ secrets.GITHUB_TOKEN }}
scanner: snyk