cloudbees-io-gha/Black Duck scan and publish to Platform

Runs Black Duck SCA scan to detect vulnerabilities, risks, and policy violations, and publishes to the CloudBees platform.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
server-urlThe URL of the Black Duck serveryes
api-tokenThe API token for Black Duckyes
cloudbees-urlCloudbees API URLnohttps://api.cloudbees.io
project-nameThe name of the project to scanno""
project-versionThe version of the project to scanno""
detect-cli-paramsAdditional parameters for the Detect CLIno""
refFlag to indicate the ref that should be archived (same as supplied to checkout)no""
workspace-dirFlag to mention the path where the checked out code will be presentno""
scan-modeFlag to mention the scan modenoINTELLIGENT
step-idThe ID of the step in the workflowno""
namedescription
critical-countA string containing the number of Critical security findings discovered during the scan.
very-high-countA string containing the number of Very High security findings discovered during the scan.
high-countA string containing the number of High security findings discovered during the scan.
medium-countA string containing the number of Medium security findings discovered during the scan.
low-countA string containing the number of Low security findings discovered during the scan.