Skip to content

Commit

Permalink
ci: add slither integration (#165)
Browse files Browse the repository at this point in the history
ci: add slither workflow

Signed-off-by: Francisco de Borja Aranda Castillejo <[email protected]>
  • Loading branch information
Francisco de Borja Aranda Castillejo authored Jul 12, 2024
1 parent 432ed72 commit b55d0e8
Show file tree
Hide file tree
Showing 2 changed files with 66 additions and 0 deletions.
59 changes: 59 additions & 0 deletions .github/workflows/slither.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
name: Slither

on:
push:
branches:
- main
pull_request:
branches:
- "*"
types:
- synchronize
- opened
- reopened
- ready_for_review

jobs:
slither:
runs-on: ubuntu-latest
strategy:
matrix:
include:
- project: "zeta-app-contracts"
file: "zeta.sarif"
- project: "zevm-app-contracts"
file: "zevm.sarif"
permissions:
contents: read
security-events: write

steps:
- name: Checkout
uses: actions/checkout@v3

- name: Install Node.js
uses: actions/setup-node@v2
with:
node-version: "18"

- name: Install Dependencies
run: yarn install

- name: Compile contracts
continue-on-error: true
run: yarn compile

- name: Run Slither on ${{ matrix.project}}
uses: crytic/slither-action@main
continue-on-error: true
with:
ignore-compile: true
sarif: ${{ matrix.file}}
node-version: "18"
target: packages/${{ matrix.project}}
fail-on: none

- name: Upload zevm-app-contracts SARIF file
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: ${{ matrix.file}}
7 changes: 7 additions & 0 deletions slither.config.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"detectors_to_exclude": "",
"compile_force_framework": "hardhat",
"hardhat_ignore_compile": true,
"npx_disable": true,
"filter_paths": "artifacts,cache,data,dist,docs,lib,node_modules,pkg,scripts,tasks,test,testing,typechain-types"
}

0 comments on commit b55d0e8

Please sign in to comment.