diff --git a/.github/workflows/datadog-sca.yaml b/.github/workflows/datadog-sca.yaml new file mode 100644 index 00000000..fd1e4fa8 --- /dev/null +++ b/.github/workflows/datadog-sca.yaml @@ -0,0 +1,43 @@ +--- +name: Datadog Software Composition Analysis + +permissions: + actions: none + checks: none + contents: read + deployments: none + issues: none + packages: none + pages: none + pull-requests: none + repository-projects: none + security-events: none + +on: + push: + branches: + - main + pull_request: + branches: + - main + +defaults: + run: + shell: bash + +jobs: + software-composition-analysis: + runs-on: ubuntu-latest + name: Datadog SBOM Generation and Upload + steps: + - name: Checkout + uses: actions/checkout@v3 + - name: Check imported libraries are secure and compliant + id: datadog-software-composition-analysis + uses: DataDog/datadog-sca-github-action@main + with: + dd_api_key: ${{ secrets.DD_API_KEY }} + dd_app_key: ${{ secrets.DD_APP_KEY }} + dd_service: mjml-api + dd_env: ci + dd_site: datadoghq.eu diff --git a/.github/workflows/datadog-static-analysis.yaml b/.github/workflows/datadog-static-analysis.yaml new file mode 100644 index 00000000..aa344bd5 --- /dev/null +++ b/.github/workflows/datadog-static-analysis.yaml @@ -0,0 +1,44 @@ +--- +name: Datadog Static Analysis + +permissions: + actions: none + checks: none + contents: read + deployments: none + issues: none + packages: none + pages: none + pull-requests: none + repository-projects: none + security-events: none + +on: + push: + branches: + - main + pull_request: + branches: + - main + +defaults: + run: + shell: bash + +jobs: + static-analysis: + runs-on: ubuntu-latest + name: Datadog Static Analyzer + steps: + - name: Checkout + uses: actions/checkout@v3 + - name: Check code meets quality and security standards + id: datadog-static-analysis + uses: DataDog/datadog-static-analyzer-github-action@v1 + with: + dd_api_key: ${{ secrets.DD_API_KEY }} + dd_app_key: ${{ secrets.DD_APP_KEY }} + dd_service: mjml-api + dd_env: ci + dd_site: datadoghq.eu + cpu_count: 2 diff --git a/static-analysis.datadog.yml b/static-analysis.datadog.yml new file mode 100644 index 00000000..034d1877 --- /dev/null +++ b/static-analysis.datadog.yml @@ -0,0 +1,3 @@ +--- +rulesets: + - docker-best-practices # ensure best practices are followed