name: Semgrep on: pull_request: {} push: branches: - master jobs: semgrep: name: Scan runs-on: ubuntu-latest steps: - uses: actions/checkout@v2 - uses: returntocorp/semgrep-action@v1 with: auditOn: push publishToken: ${{ secrets.SEMGREP_APP_TOKEN }} publishDeployment: 1395