cloudbees-io-gha/Snyk SCA scan and publish to Unify Platform
Runs Snyk SCA scan to detect security vulnerabilities in open source dependencies and publishes to the Unify platform.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Maintainedlast commit Jan 19, 2026
- License
- MIT
Pinned Snippet
uses: cloudbees-io-gha/snyk-sca-publish@4c258fb66565e447636d45a495e1ef9462c78a4d # v1tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| cloudbees-url | Cloudbees API URL | no | https://api.cloudbees.io |
| snyk-token | Snyk API token for authentication | yes | — |
| org-id | Snyk organization ID | yes | — |
| cli-params | Command line params for snyk open source scan | no | — |
| build-directory | Build directory that holds the build tools | no | — |
| ref | Flag to indicate the ref that should be archived (same as supplied to checkout). | no | "" |
| workspace-dir | Flag to mention the path where the checked out code will be present. | no | "" |
| step-id | The ID of the step in the workflow | no | "" |
Outputs
| name | description |
|---|---|
| critical-count | A string containing the number of Critical security findings discovered during the scan. |
| very-high-count | A string containing the number of Very High security findings discovered during the scan. |
| high-count | A string containing the number of High security findings discovered during the scan. |
| medium-count | A string containing the number of Medium security findings discovered during the scan. |
| low-count | A string containing the number of Low security findings discovered during the scan. |