pombredanne/Black Duck GH Scan Action Directguidance

Black Duck Scanning NEW VERSION for GitHub CI/CD Workflows

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stalelast commit Apr 19, 2022
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: pombredanne/blackduck-scan-directguidance@40abcd809d2b6e1f8ee78fdcfb87ec3de3657e80 # v5

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
debugDebuggingno0
bd_urlBlack Duck URLyes
bd_tokenBlack Duck API Tokenyes
bd_trustcertTrust Black Duck server certificateno
projectProject name in the Black Duck serverno
versionProject version name in the Black Duck serverno
modeScanning mode, intelligent or rapidnorapid
fileLocation of the related file in the repositoryno
output_folderDirectory in which to save the rapid scan outputnoblackduck-output
fix_prGenerate a Fix PR for each insecure componentnofalse
comment_on_prComment on a pull requestnofalse
sarifOutput file for SARIFno
incremental_resultsIncremental analysisno
upgrade_majorRecommend upgrade guidance to major, not just minor, versionsno
no_files_checkSkip check of GH commit/PR for changed package manager config filesno
detect_optsPassthrough options to Detect, comma delimited, exclude leading hyphensno

no outputs