| name | integrating-sast-into-github-actions-pipeline |
| description | Use when this skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring automated code scanning on pull requests and pushes, tuning rules to reduce false positives, uploading SARIF results to GitHub Advanced Security, and establishing quality gates that block merges when high-severity vulnerabilities are detected. |
| domain | cybersecurity |
| tags | ["devsecops","cicd","sast","codeql","semgrep","secure-sdlc"] |
| subdomain | devsecops |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.PS-01","GV.SC-07","ID.IM-04","PR.PS-04"] |
Integrating Sast Into Github Actions Pipeline
Overview
Cybersecurity skill for integrating sast into github actions pipeline. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"integrating sast into github actions pipeline"
-
"This skill covers integrating Static Application Security Testing (SAST) tools—C"
-
When development teams need automated code-level vulnerability detection on every pull request
-
When security teams require consistent SAST enforcement across all repositories in an organization
-
When migrating from manual or periodic security reviews to continuous security testing
-
When compliance frameworks (SOC 2, PCI DSS, NIST SSDF) require evidence of automated code analysis
-
When multiple languages coexist in a monorepo and need unified scanning under one workflow
Do not use for runtime vulnerability detection (use DAST instead), for scanning third-party dependencies (use SCA tools like Snyk), or for infrastructure-as-code scanning (use Checkov or tfsec).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- GitHub repository with GitHub Actions enabled
- GitHub Advanced Security license (required for CodeQL on private repos; free for public repos)
- Semgrep account for managed rules and Semgrep App dashboard (free tier available)
- Repository code in a supported language: Python, JavaScript/TypeScript, Java, C/C++, C#, Go, Ruby, Swift, Kotlin
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}