Skip to content

chore: migrate to pnpm and Biome, refresh tooling deps #775

chore: migrate to pnpm and Biome, refresh tooling deps

chore: migrate to pnpm and Biome, refresh tooling deps #775

Workflow file for this run

name: Veracode Scans
on:
pull_request:
types: [opened, synchronize, reopened]
merge_group:
types: [ checks_requested ]
push:
branches: [main]
permissions:
contents: write
jobs:
veracode:
runs-on: "ubuntu-latest"
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Create package (zip)
# Scan shipped code only: exclude tests, build-time scripts, and generated output.
# .agents/ and .claude/ hold vendored AI-agent tooling (skills, prompts) that is
# developer-only and never shipped; .claude/skills/* symlinks into .agents/, so both
# paths must be excluded or the same file is scanned twice.
run: zip -r package.zip . -x ".git/*" "tests/*" "docs/*" "*.md" "images/*" "tomtom-mcp.mcpb" ".github/*" ".agents/*" ".claude/*" "scripts/*" "*.test.ts" "node_modules/*" "dist/*" "coverage/*" "veracode-pipeline-scan-baseline-file.json"
- name: Veracode Pipeline Scan (PR)
if: ${{ github.event_name == 'pull_request' }}
uses: veracode/Veracode-pipeline-scan-action@v1.0.20
with:
vid: ${{ secrets.VERACODE_API_ID }}
vkey: ${{ secrets.VERACODE_API_KEY }}
file: "package.zip"
# Known findings are baselined (triage: docs/veracode-findings-triage.md),
# so only NEW findings fail the build. To refresh the baseline, download
# the veracode-full-results artifact from an accepted scan and replace
# the baseline file.
baseline_file: "veracode-pipeline-scan-baseline-file.json"
fail_build: true
- name: Fail if the scan did not actually run
# The scan action exits 0 even when scan creation fails (e.g. HTTP 401
# on invalid credentials), which produced green checks with no scan.
# A completed scan always writes results.json.
if: ${{ github.event_name == 'pull_request' }}
run: test -s results.json || { echo "::error::Veracode pipeline scan produced no results (credential or upload failure) — check the scan step log"; exit 1; }
- name: Upload full scan results
# The scan action only uploads filtered_results.json; the full
# results.json is needed to inspect findings and to (re)generate the
# baseline file (see docs/veracode-findings-triage.md).
if: ${{ github.event_name == 'pull_request' }}
uses: actions/upload-artifact@v4
with:
name: veracode-full-results
path: results.json
- name: Veracode Policy Scan (main)
if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }}
uses: veracode/veracode-uploadandscan-action@0.2.9
with:
vid: ${{ secrets.VERACODE_API_ID }}
vkey: ${{ secrets.VERACODE_API_KEY }}
appname: tomtom-international.tomtom-mcp
filepath: "package.zip"
deleteincompletescan: 2