cloudbees-io/coverity-hybrid

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 9, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: cloudbees-io/coverity-polaris-sast-scan-code@61463415d1b0b9cdf0a634378a32bc25c597e891 # v2.0.2

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
server-urlServer URLyes
api-tokenAPI tokenyes
refFlag to indicate the ref that should be archived (same as supplied to checkout)no""
workspace-dirFlag to mention the path where the checked out code will be presentno""
namedescription
critical-countA string containing the number of Critical security findings discovered during the scan.
very-high-countA string containing the number of Very High security findings discovered during the scan.
high-countA string containing the number of High security findings discovered during the scan.
medium-countA string containing the number of Medium security findings discovered during the scan.
low-countA string containing the number of Low security findings discovered during the scan.