blackduck-ai-poc/Black Duck Security Scan

Find and fix software weaknesses and vulnerabilities during development, before you ship or deploy!

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit May 26, 2025
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: blackduck-ai-poc/poc@ec4b1c1ee94732ff0f6e956ab1890aef908fe7a1 # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
coverity_urlCoverity urlno
coverity_userCoverity user nameno
coverity_passphraseCoverity passwordno
coverity_project_nameCoverity Project Nameno
coverity_stream_nameCoverity Stream Nameno
coverity_install_directoryCoverity Install Directoryno
coverity_policy_viewCoverity Policy Viewno
coverity_localFlag to enable/disable to run coverity scan locally.no
coverity_versionIf provided, Black Duck Security Action will download specific version of coverity thin client to use.no
coverity_prComment_enabledFlag to enable pull request comments for new issues found in the Coverity scanno
coverity_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
coverity_build_commandBuild command for Coverityno
coverity_clean_commandClean command for Coverityno
coverity_config_pathCoverity config file path (.yaml/.yml/.json)no
coverity_argsAdditional Coverity Arguments separated by spaceno
bridge_coverity_versionIf provided, Black Duck Security Action will download specific version of coverity thin client to use.no
polaris_access_tokenPolaris Access Tokenno
polaris_application_namePolaris Application Nameno
polaris_project_namePolaris Project Nameno
polaris_assessment_typesPolaris Assess Types SAST/SCAno
polaris_server_urlPolaris Server URLno
polaris_prComment_enabledFlag to enable pull request comments based on Polaris scan resultno
polaris_prComment_severitiesList of severities for which the PR Comments should be createdno
polaris_triagePolaris Triageno
polaris_branch_namePolaris branch nameno
polaris_branch_parent_namePolaris parent branch nameno
polaris_test_sca_typePolaris test type to trigger signature scan or package manager scanno
polaris_reports_sarif_createFlag to enable/disable Polaris SARIF report generationno
polaris_reports_sarif_file_pathFile path including file name where Polaris SARIF report should be createdno
polaris_reports_sarif_severitiesIndicates what SAST/SCA issues severity categories to include in Polaris SARIF file reportno
polaris_reports_sarif_groupSCAIssuesFlag to enable/disable Component-Version grouping for SCA Issues in Polaris SARIF report rules sectionno
polaris_reports_sarif_issue_typesEnum to indicate which assessment issues type to include in Polaris SARIF file reportno
polaris_upload_sarif_reportFlag to enable/disable uploading of Polaris SARIF report to GitHub Advanced Securityno
polaris_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
polaris_assessment_modeThe test mode type of this scanno
project_directoryThe project source directory. Defaults to repository root directory. Set this to specify a custom folder that is other than repository rootno
project_source_archiveThe zipped source file path. It overrides the project directory settingno
project_source_preserveSymLinksFlag indicating whether to preserve symlinks in the source zipno
project_source_excludesA list of git ignore pattern strings that indicate the files need to be excluded from the zip fileno
bridgecli_install_directoryBridge CLI Install Directoryno
bridgecli_download_urlURL to download bridge fromno
blackducksca_urlURL for blackduck hubno
blackducksca_tokenAPI token to access blackduckno
detect_install_directoryDirectory to find or install detectno
blackducksca_scan_fullScan Mode. (true for intelligent scan & false for rapid scan)no
blackducksca_scan_failure_severitiesIf provided, Black Duck will break the build if any issues produced match one of the given severitiesno
blackducksca_fixpr_enabledIf set as true, separate Fix PRs will be created if vulnerability is found after scanno
blackducksca_fixpr_maxCountMaximum number of Pull Requests to be created that violate policiesno
blackducksca_fixpr_filter_severitiesIf provided, Fix PRs will be created only for given severitiesno
blackducksca_fixpr_useUpgradeGuidanceFlag to enable long term upgrade guidanceno
bridgecli_download_versionIf provided, Black Duck Security Action will configure the version of Bridgeno
blackducksca_prComment_enabledFlag to enable pull request comments for new issues found in the Black Duck scanno
blackducksca_reports_sarif_createFlag to enable/disable Black Duck SARIF report generationno
blackducksca_reports_sarif_file_pathFile path including file name where Black Duck SARIF report should be createdno
blackducksca_reports_sarif_severitiesIndicates what SAST/SCA issues severity categories to include in Black Duck SARIF file reportno
blackducksca_reports_sarif_groupSCAIssuesFlag to enable/disable Component-Version grouping for SCA Issues in Black Duck SARIF report rules sectionno
blackducksca_upload_sarif_reportFlag to enable/disable uploading of Black Duck SARIF report to GitHub Advanced Securityno
blackducksca_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
detect_search_depthNumber indicating the search depth in the source directoryno
detect_argsAdditional Black Duck Arguments separated by spaceno
detect_config_pathBlack Duck config file path (.properties/.yml)no
blackducksca_policy_badges_createTo enable creation of badges on the GitHub repositoryno
blackducksca_policy_badges_maxCountTo limit number of badges to be displayed on the GitHub repositoryno
srm_urlSRM Urlno
srm_apikeySRM Api Keyno
srm_assessment_typesSRM Assessment Typesno
srm_project_nameSRM project nameno
srm_branch_nameSRM branch nameno
srm_project_idSRM branch Idno
srm_branch_parentSRM branch parentno
srm_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
coverity_execution_pathCoverity execution pathno
detect_execution_pathBlack Duck execution pathno
github_tokenGithub token to be used for git related rest operationno
include_diagnosticsTo include diagnostics info and export as zipno
diagnostics_retention_daysNumber of days to keep the diagnostics files downloadableno
bridge_network_airgapIf provided, Black Duck Security Action will be using local network to download and execute bridge .no
network_airgapIf provided, Black Duck Security Action will be using local network to download and execute bridge .no
polaris_policy_badges_createTo enable creation of badges on the GitHub repository for polarisno
polaris_policy_badges_maxCountTo limit number of badges to be displayed on the GitHub repository for polarisno
mark_build_statusSpecify the build status if policy violating issues are found.nofailure
namedescription
statusThe numeric exit code returned by the Black Duck Security Scan.