home-office-digital/Checkov SAST Scan
Runs a Checkov scan on source code using central policies.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Activelast commit Jul 9, 2026
- License
- None
Pinned Snippet
uses: home-office-digital/core-cloud-workflow-checkov-sast-scan@5036e61fa50079eb9dc835a1ed557a6e7ae5d848 # 1.19.0tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| path | The path to the directory to scan. | no | . |
| version-tag | The git ref of the central policies repo to use. | no | main |
| org | Set if using GHES instance | no | Home-Office-Digital |
| EXEMPTIONS_APP_ID | Exemptions secret applied by the Core Cloud team when exceptions are approved and required. | no | "" |
| EXEMPTIONS_APP_PRIVATE_KEY | Exemptions secret applied by the Core Cloud team when exceptions are approved and required. | no | "" |
Outputs
no outputs