sabinghost19/Security Scan Attestor

Aggregate gitleaks (secrets), Semgrep (SAST) and checkov (IaC) results into a signed security-scan Cosign attestation

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
imageImmutable image reference in digest form (ghcr.io/...@sha256:...)yes
commit-shaGit commit SHA associated with the buildyes
serviceService name for multi-image apps (api | worker); empty for single-image appsno""
gitleaks-reportPath to the gitleaks JSON report (secrets)no""
semgrep-sarifPath to the Semgrep SARIF report (SAST)no""
checkov-sarifPath to the checkov SARIF report (IaC: Dockerfile + K8s manifests)no""
sast-block-severityMinimum SAST severity that CI considers blocking (low|medium|high|critical). Recorded in gating; enforcement is upstream/operator.nocritical
attestation-typeCosign attestation type (predicate type URI)nohttps://devsecops.licenta.ro/attestations/security-scan/v1
namedescription
predicate-pathPath to the generated security-scan predicate JSON file
resultCI gating verdict computed from the reports (pass|fail)
secrets-totalTotal number of secret findings