basel5001/DevSecOps Security Pipeline

Comprehensive security scanning with SAST, dependency scanning, container scanning, IaC scanning, secrets detection, and AI-powered analysis.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 11, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: basel5001/devsecops-pipeline@514c0c38265824e2e42b65445c333b56545e52d4 # no releases — HEAD as of 2026-07-13

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to scan (defaults to repository root)no.
fail-on-criticalFail the action if critical findings are detectednotrue
bedrock-enabledEnable AWS Bedrock AI analysisnofalse
bedrock-model-idAWS Bedrock model IDnoanthropic.claude-3-haiku-20240307-v1:0
severity-thresholdMinimum severity to report (CRITICAL, HIGH, MEDIUM, LOW)noMEDIUM
upload-artifactUpload scan results as an artifactnotrue
namedescription
risk-scoreOverall risk score (0-100)
report-pathPath to the generated HTML report
total-findingsTotal number of findings
critical-countNumber of critical findings