actions-marketplace-validations/Veracode Software Composition Analysis

An action to execute Veracode Agent-Based SCA and import findings as issues

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
Runtime
Deprecated runtime
namedescriptionrequireddefault
github_tokenAuthorization token to query and create issuesyes
quicknofalse
update_advisorShow update advisornofalse
urlA git URL to work with in case the scan is not for the current repositoryno""
min-cvss-for-issueThe minimum CVSS value for vulnerability to be added as an issueno0
fail-on-cvssThe maximum allowed cvss in found vulnerabilities to pass the stepno10
create-issuesAn attribute to instruct the action to create an issue from found vulnerability or just simple text outputnofalse
pathA path within the repository where the build definition startsno.
debugRun the SRCCLR in debug modenofalse
skip-collectorsRun the SRCCLR with the `--skip-collectors` optionsnofalse
allow-dirtyRun the SRCCLR with the `--allow-dirty` optionnofalse
recursiveRun the SRCCLR with the `--recursive` optionnofalse

no outputs