name: DevSkim on: pull_request: branches: [main] merge_group: workflow_dispatch: schedule: # set schedule to run at 2AM PT on Saturdays - cron: "0 9 * * Sat" jobs: lint: name: DevSkim runs-on: ubuntu-latest permissions: # required for all workflows security-events: write # only required for workflows in private repositories actions: read contents: read steps: - name: Checkout code uses: actions/checkout@v6 - name: Run DevSkim scanner uses: microsoft/DevSkim-Action@v1 - name: Upload DevSkim scan results to GitHub Security tab uses: github/codeql-action/upload-sarif@v3 with: sarif_file: devskim-results.sarif