bpsizemore/Nosey Parker

Scan repository for secrets

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stalelast commit Mar 4, 2024
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: bpsizemore/noseyparker-action@12ee49ccd667c8ce63eb5a39e8198019a26eb221 # v1.0.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
local-outputecho human-readable findings to consolenotrue
report-nameFile name for the reports without the extensionnoreport
report-format-humanupload human readable (txt) formatted reportnofalse
report-format-jsonupload json formatted reportnofalse
report-format-jsonlupload jsonl formatted reportnofalse
report-format-sarifupload sarif formatted reportnofalse
scan-directoryrelative directory of the repo to scan from $GITHUB_WORKSPACEnomain
fail-on-findingset to true to interrupt the pipeline if there are any findingsnofalse
scan-argsArguments to pass to scan - this is passed after datastore and scan-directory are specified. Arguments like --github-user will override the scan directory for local scanning.no""
namedescription
timeThe initial runtime.
np_status_codeStatus code of the noseyparker scan command.
np_statusDescriptive status of noseyparker scan command.