boostsecurityio/Boost Security Scanner

Scans a repository for security vulneratibilities

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Feb 4, 2025
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: boostsecurityio/boostsec-scanner-github@c164a3b136a743feb06129452c06680c6af7c878 # v4

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
additional_argsAdditional CLI arguments to passno""
api_enabledOptional setting to enable offline modetrue
api_endpointBoost API endpointyeshttps://api.boostsecurity.io
api_tokenBoost API tokenyes
cli_versionScanner version1
ignore_failureIgnore any exception returned by the scanner clifalse
log_levelSet the cli logging level""
main_branchOptional override for main branch detection""
pre_scan_cmdOptional command to run before scanning""
registry_moduleModule within the scanner registry to execute""
scanner_idOptional identifier to uniquely identify the scanner""
scan_labelOptional identifier to identify a a monorepo component""
scan_pathOptional relative path to scan""
scan_timeoutMaximum amount of time a diff scan should complete in (deprecated)""
scan_diff_timeoutMaximum amount of time a diff scan should complete in""
scan_main_timeoutMaximum amount of time a main scan should complete in""
trigger_idBoost API workflow trigger id""

no outputs