BigHugger
sk Skill · mukul975

integrating-sast-into-github-actions-pipeline

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and merge-blocking quality gates for high-severity findings. Use when adding automated code vulnerability detection to CI, enforcing consistent SAST org-wide, or producing SOC 2/PCI DSS/NIST SSDF compliance evidence.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashsecure-sdlcPythonsemgrepcodeqlsastyamlpythoncicddevsecops
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0.0
Licence
Apache-2.0
Host stars
33k
Host language
Python