semgrep:# A Docker image with Semgrep installed.image: semgrep/semgrep
# Run the "semgrep ci" command on the command line of the docker image.script: semgrep ci
rules:# Allow triggering a scan manually from the GitLab UI-if: $CI_PIPELINE_SOURCE == "web"
# Scan changed files in MRs, (diff-aware scanning):-if: $CI_MERGE_REQUEST_IID
# Scan mainline (default) branches and report all findings.-if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
variables:# Connect to Semgrep AppSec Platform through your SEMGREP_APP_TOKEN.# Generate a token from Semgrep AppSec Platform > Settings# and add it as a variable in your GitLab CI/CD project settings.SEMGREP_APP_TOKEN: $SEMGREP_APP_TOKEN
こんな感じらしいです
当然ですがローカルで実行してエラーをすべて解消しないと CI してもエラーになるので注意してください