diff --git a/templates/sast.yml b/templates/sast.yml index 927d012..6dad115 100644 --- a/templates/sast.yml +++ b/templates/sast.yml @@ -154,9 +154,11 @@ semgrep-sast: - '**/*.swift' - '**/*.m' - '**/*.kt' - - '**/*.yml' - - '**/*.yaml' - '**/*.properties' + - '**/application*.yml' + - '**/bootstrap*.yml' + - '**/application*.yaml' + - '**/bootstrap*.yaml' ## In case gitlab-advanced-sast already covers all the files that semgrep-sast would have scanned - if: '$CI_COMMIT_BRANCH && $GITLAB_FEATURES =~ /\bsast_advanced\b/ && @@ -190,9 +192,11 @@ semgrep-sast: - '**/*.kt' - '**/*.cjs' - '**/*.mjs' - - '**/*.yml' - - '**/*.yaml' - '**/*.properties' + - '**/application*.yml' + - '**/bootstrap*.yml' + - '**/application*.yaml' + - '**/bootstrap*.yaml' sobelow-sast: extends: .sast-analyzer