name: RepoPilot SARIF
on:
pull_request:
push:
branches:
- main
permissions:
contents: read
security-events: write
jobs:
repopilot:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Install RepoPilot
run: cargo install repopilot
- name: Run RepoPilot SARIF scan
run: repopilot scan . --format sarif --output repopilot.sarif
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v4
with:
sarif_file: repopilot.sarif
category: repopilot