Skip to content
This repository has been archived by the owner on Mar 24, 2024. It is now read-only.

Commit

Permalink
better docs
Browse files Browse the repository at this point in the history
  • Loading branch information
Haoxi Tan committed Jun 5, 2023
1 parent d13c224 commit b050a1a
Showing 1 changed file with 9 additions and 1 deletion.
10 changes: 9 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# pypi auto scanner

A github action that fetches the latest pypi packages and scans them. Report any issues found in issues.
A github action that fetches the latest pypi packages and scans them using semgrep rules in [h4sh-semgrep-rules](https://github.com/h4sh5/h4sh-semgrep-rules). Currently stores the JSON report in github action artifacts.

## Fetching the latest report

You will need a Github API token to do this. Export the token to `GH_TOKEN` by running `export GH_TOKEN=ghp...`

Then run `./fetch_latest_report.sh` and `unzip report.zip`

You can parse the JSON report for stuff using `parse-semgrep-json.py` as an example.


0 comments on commit b050a1a

Please sign in to comment.