concord-dev/Concord Compliance Gate

Evaluate compliance controls as code and gate the PR, publishing results to GitHub code scanning (SARIF).

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
versionConcord release to use (a git tag like v0.3.0, or 'latest').latest
controlsPath to the controls directory.controls
configPath to concord.yaml.concord.yaml
frameworkRestrict evaluation to a single framework id (optional).""
fixturesRun in fixtures-only mode (offline; no live collectors).false
fail-on-warningsFail the gate when a control emits warnings, not just failures.false
sarif-fileWhere to write the SARIF report.concord.sarif
upload-sarifUpload the SARIF report to GitHub code scanning (needs security-events: write).true
working-directoryDirectory to run concord in..

no outputs