{"repo":"HCL-TECH-SOFTWARE/appscan-codesweep-action","free":true,"listed":false,"github":"https://github.com/HCL-TECH-SOFTWARE/appscan-codesweep-action","clone":"git clone https://github.com/HCL-TECH-SOFTWARE/appscan-codesweep-action.git","description":"Integrate static security testing with HCL AppScan CodeSweep with Github.","language":null,"stars":22,"topics":["appscan","codesweep","github","action","github-actions","sast","scanning","security","security-automation","security-scanner"],"license":null,"category":"security-tools","readme_excerpt":"HCL AppScan CodeSweep Github Action Your GitHub code is better and more secure with HCL AppScan CodeSweep for GitHub. For free. The HCL AppScan CodeSweep GitHub Action enables you to check your code on every pull request. The action identifies vulnerabilities in changed code with every update. But more than just identifying issues, the HCL AppScan CodeSweep GitHub Action tells you what you need to know to mitigate issues — before they make it to the main branch. Usage 1. Ensure that the \"Workflow permissions\" for your repository are set to \"Read and write permissions\". This allows Codesweep to scan your files and create checkruns and annotations for the issues it finds. You can access these settings by going to Settings - Actions - General. 2. To scan code changes when a pull request is opened, add the following file to your repository under .github/workflows/codesweep.yml or update an existing workflow file: Note If you use checkout@v2 or later you must set fetch-depth to 0. For example: Optional You can publish security issues to ASoC or AppScan 360 when a pull request is merged. To do so: 1. (ASoC only) Register on HCL AppScan on Cloud (ASoC) to generate your API key/secret. 2. After logging into ASoC or AppScan 360, go to the API page to generate your API key/secret pair. These must be used in the asoc key and asoc secret parameters for the action. It's recommended to store them as secrets in your repository. 3. Add the following file to your repository under .github/work","default_branch":null,"files":null,"tree":[],"storefront":"/r/HCL-TECH-SOFTWARE","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/HCL-TECH-SOFTWARE/appscan-codesweep-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}