diff --git a/templates/sast.yml b/templates/sast.yml index 418ad1e..1ce3f54 100644 --- a/templates/sast.yml +++ b/templates/sast.yml @@ -66,6 +66,7 @@ gitlab-advanced-sast: - '**/*.py' - '**/*.go' - '**/*.java' + - '**/*.jsp' - '**/*.js' - '**/*.jsx' - '**/*.ts' @@ -73,6 +74,7 @@ gitlab-advanced-sast: - '**/*.cjs' - '**/*.mjs' - '**/*.cs' + - '**/*.rb' brakeman-sast: extends: .deprecated-16.8 @@ -136,7 +138,7 @@ semgrep-sast: "$[[ inputs.excluded_analyzers ]]" !~ /gitlab-advanced-sast/ && "$[[ inputs.run_advanced_sast ]]" == "true"' variables: - SAST_EXCLUDED_PATHS: "$DEFAULT_SAST_EXCLUDED_PATHS, **/*.py, **/*.go, **/*.java, **/*.js, **/*.jsx, **/*.ts, **/*.tsx, **/*.cjs, **/*.mjs, **/*.cs" + SAST_EXCLUDED_PATHS: "$DEFAULT_SAST_EXCLUDED_PATHS, **/*.py, **/*.go, **/*.java, **/*.js, **/*.jsx, **/*.ts, **/*.tsx, **/*.cjs, **/*.mjs, **/*.cs, **/*.rb" exists: - '**/*.c' - '**/*.cc' @@ -151,7 +153,6 @@ semgrep-sast: - '**/*.php' - '**/*.swift' - '**/*.m' - - '**/*.rb' - '**/*.kt' ## In case gitlab-advanced-sast already covers all the files that semgrep-sast would have scanned - if: '$CI_COMMIT_BRANCH &&