cloudbees-io-gha/Snyk IaC scan and publish to Unify Platform

Runs Snyk IaC scan to detect security vulnerabilities and misconfigurations and publishes to the Unify platform.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Jan 13, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: cloudbees-io-gha/snyk-iac-publish@035512b21fcb8c9092cbd3b23985ac731fd340c7 # v1

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
cloudbees-urlCloudbees API URLnohttps://api.cloudbees.io
snyk-tokenSnyk API token for authenticationyes
org-idSnyk organization IDyes
severity-thresholdSeverity threshold for scan results (low, medium, high, critical)no
refFlag to indicate the ref that should be archived (same as supplied to checkout).no""
workspace-dirFlag to mention the path where the checked out code will be present.no""
step-idThe ID of the step in the workflowno""
namedescription
critical-countA string containing the number of Critical security findings discovered during the scan.
very-high-countA string containing the number of Very High security findings discovered during the scan.
high-countA string containing the number of High security findings discovered during the scan.
medium-countA string containing the number of Medium security findings discovered during the scan.
low-countA string containing the number of Low security findings discovered during the scan.