Files
sec-actions/README.md
T
2026-03-24 21:15:45 +01:00

1.2 KiB

OSV-Scanner Actions

Gitea-compatible composite actions for Google OSV-Scanner: install the CLI, cache the offline vulnerability database, merge SARIF reports, and extract container image references from manifests.

Actions

Directory Purpose
setup-osv-scanner Download and cache a pinned osv-scanner release (Linux amd64 / arm64), SHA256-verified.
setup-osv-db Restore or populate selected ecosystem zips via curl; cache key includes hour bucket + ecosystem list.
merge-sarif-files Merge multiple SARIF files into one (tool-agnostic).
get-images-from-files Parse Dockerfiles, Kubernetes YAML, Compose, and Helmfile values for image refs (useful with osv-scanner scan image …).

Workflows

  • CI (.gitea/workflows/ci.yaml): tests the actions above on pull_request.
  • CD / Prerelease: tag bump workflows unchanged (no scanner).

Documentation

Each action directory has its own README.md with inputs, outputs, and examples.