aah20/VulnTruth Scanner Reality Check
Compare exported Trivy, Grype, and OSV findings and explain decision-relevant disagreements.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Activelast commit Aug 13, 2026
- License
- None
Pinned Snippet
uses: aah20/vulntruth@d918d0d84b5f3282241078fd636a4b50040a6632 # no releases — HEAD as of 2026-08-29tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| artifact | Immutable artifact name or digest represented by the reports. | yes | — |
| trivy-report | Path to a Trivy JSON report. | no | — |
| grype-report | Path to a Grype JSON report. | no | — |
| osv-report | Path to an OSV-Scanner JSON report. | no | — |
| kev-catalog | Path to a CISA KEV JSON catalog or controlled snapshot. | no | — |
| output-directory | Directory for JSON and Markdown evidence. | no | vulntruth-artifacts |
| fail-on | Set to patch-now to fail when a consensus KEV requires immediate patching. | no | none |
Outputs
no outputs