Skip to content

Detekt

Detekt #5

Workflow file for this run

name: Detekt
on:
schedule:
- cron: "39 6 * * 2"
workflow_call:
secrets:
## Secrets: Buildless API key
BUILDLESS_APIKEY:
required: true
description: "Buildless API key"
workflow_dispatch:
secrets:
BUILDLESS_APIKEY:
required: true
description: "Buildless API key"
env:
DETEKT_RELEASE_TAG: v1.23.0
jobs:
scan:
name: Detekt
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@cba0d00b1fc9a034e1e642ea0f1103c282990604 # v2.5.0
with:
egress-policy: audit
- name: "Setup: Checkout"
uses: actions/checkout@c85c95e3d7251135ab7dc9ce3241c5835cc595a9 # v3
- name: "Setup: JDK 19"
uses: buildjet/setup-java@3b5edd4799eb848d92664003cb1e6f74db868f19 # v3
with:
distribution: "adopt-hotspot"
java-version: "19"
- name: "Setup: Detekt"
continue-on-error: true
run: |
dest=$( mktemp -d )
curl --request GET \
--url https://github.com/detekt/detekt/releases/download/v1.23.0/detekt-cli-1.23.0-all.jar \
--silent \
--location \
--output $dest/detekt
chmod a+x $dest/detekt
echo $dest >> $GITHUB_PATH
- name: "Analysis: Detekt"
continue-on-error: true
run: |
detekt --input ${{ github.workspace }} --report sarif:${{ github.workspace }}/detekt.sarif.json
- name: "Fixup: SARIF Locations"
continue-on-error: true
run: |
echo "$(
jq \
--arg github_workspace ${{ github.workspace }} \
'. | ( .runs[].results[].locations[].physicalLocation.artifactLocation.uri |= if test($github_workspace) then .[($github_workspace | length | . + 1):] else . end )' \
${{ github.workspace }}/detekt.sarif.json
)" > ${{ github.workspace }}/detekt.sarif.json
- name: "Report: SARIF Upload"
uses: github/codeql-action/upload-sarif@0ba4244466797eb048eb91a6cd43d5c03ca8bd05 # v2
continue-on-error: true
with:
sarif_file: ${{ github.workspace }}/detekt.sarif.json
checkout_path: ${{ github.workspace }}