aah20/VulnTruth Scanner Reality Check

Compare exported Trivy, Grype, and OSV findings and explain decision-relevant disagreements.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Aug 13, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: aah20/vulntruth@d918d0d84b5f3282241078fd636a4b50040a6632 # no releases — HEAD as of 2026-08-29

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
artifactImmutable artifact name or digest represented by the reports.yes
trivy-reportPath to a Trivy JSON report.no
grype-reportPath to a Grype JSON report.no
osv-reportPath to an OSV-Scanner JSON report.no
kev-catalogPath to a CISA KEV JSON catalog or controlled snapshot.no
output-directoryDirectory for JSON and Markdown evidence.novulntruth-artifacts
fail-onSet to patch-now to fail when a consensus KEV requires immediate patching.nonone

no outputs