# OSV-Scanner Actions Gitea-compatible composite actions around [Google OSV-Scanner](https://github.com/google/osv-scanner): cache the offline vulnerability database, merge SARIF reports, and extract container image references from manifests. Install the `osv-scanner` CLI from [upstream releases](https://github.com/google/osv-scanner/releases) (or your package manager) in your workflow. ## Actions | Directory | Purpose | | ---------------------- | ----------------------------------------------------------------------- | | `setup-osv-db` | Restore or populate selected ecosystem zips via curl; cache key includes hour bucket + ecosystem list. | | `merge-sarif-files` | Merge multiple SARIF files into one (tool-agnostic). | | `get-images-from-files`| Parse Dockerfiles, Kubernetes YAML, Compose, and Helmfile values for image refs (useful with `osv-scanner scan image …`). | ## Workflows - **CI** (`.gitea/workflows/ci.yaml`): tests the actions above on `pull_request`. - **CD / Prerelease**: tag bump workflows unchanged (no scanner). ## Documentation Each action directory has its own `README.md` with inputs, outputs, and examples.