diff --git a/README.md b/README.md index 9bae6f5..77565e8 100644 --- a/README.md +++ b/README.md @@ -22,7 +22,12 @@ jobs: SCS: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@v4 + + # Required for security-code-scan/security-code-scan-results-action@v1 + - uses: actions/setup-dotnet@v4 + with: + dotnet-version: '3.1.x' - name: Set up projects uses: security-code-scan/security-code-scan-add-action@v1.2 @@ -36,7 +41,7 @@ jobs: uses: security-code-scan/security-code-scan-results-action@v1 - name: Upload sarif - uses: github/codeql-action/upload-sarif@v1 + uses: github/codeql-action/upload-sarif@v3 ``` For .NET 4.x example see [FullDotNetWebApp demo repository](https://github.com/security-code-scan/FullDotNetWebApp). diff --git a/action.yml b/action.yml index 7134c60..2e0ed17 100644 --- a/action.yml +++ b/action.yml @@ -14,7 +14,7 @@ runs: - name: Convert sarif shell: bash run: | - dotnet tool install --global Sarif.Multitool --version 2.3.10 + dotnet tool install --global Sarif.Multitool --version 4.5.4 outputDir="${{ inputs.sarif_directory }}" mkdir $outputDir @@ -70,7 +70,7 @@ runs: i=0 for sarifFile in $(find ./ -name '*.sarif') do - sarif transform $sarifFile --output $sarifFile -f --sarif-output-version Current + sarif rewrite $sarifFile --output $sarifFile --sarif-output-version Current --log ForceOverwrite node convert.js $sarifFile $sarifFile mv $sarifFile $outputDir/$((i++)).sarif done