synopsys-sig/Synopsys Action

Deprecated:Please use Black Duck Security Scan "https://github.com/marketplace/actions/black-duck-security-scan"

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
coverity_urlCoverity urlno
coverity_userCoverity user nameno
coverity_passphraseCoverity passwordno
coverity_project_nameCoverity Project Nameno
coverity_stream_nameCoverity Stream Nameno
coverity_install_directoryCoverity Install Directoryno
coverity_policy_viewCoverity Policy Viewno
coverity_repository_nameRepository Nameno
coverity_branch_nameBranch nameno
coverity_localFlag to enable/disable to run coverity scan locally.no
coverity_versionIf provided, Synopsys Action will download specific version of coverity thin client to use.no
coverity_prComment_enabledFlag to enable pull request comments for new issues found in the Coverity scanno
coverity_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
coverity_build_commandBuild command for Coverityno
coverity_clean_commandClean command for Coverityno
coverity_config_pathCoverity config file path (.yaml/.yml/.json)no
coverity_argsAdditional Coverity Arguments separated by spaceno
bridge_coverity_versionIf provided, Synopsys Action will download specific version of coverity thin client to use.no
polaris_access_tokenPolaris Access Tokenno
polaris_application_namePolaris Application Nameno
polaris_project_namePolaris Project Nameno
polaris_assessment_typesPolaris Assess Types SAST/SCAno
polaris_server_urlPolaris Server URLno
polaris_prComment_enabledFlag to enable pull request comments based on Polaris scan resultno
polaris_prComment_severitiesList of severities for which the PR Comments should be createdno
polaris_triagePolaris Triageno
polaris_branch_namePolaris branch nameno
polaris_branch_parent_namePolaris parent branch nameno
polaris_test_sca_typePolaris test type to trigger signature scan or package manager scanno
polaris_reports_sarif_createFlag to enable/disable Polaris SARIF report generationno
polaris_reports_sarif_file_pathFile path including file name where Polaris SARIF report should be createdno
polaris_reports_sarif_severitiesIndicates what SAST/SCA issues severity categories to include in Polaris SARIF file reportno
polaris_reports_sarif_groupSCAIssuesFlag to enable/disable Component-Version grouping for SCA Issues in Polaris SARIF report rules sectionno
polaris_reports_sarif_issue_typesEnum to indicate which assessment issues type to include in Polaris SARIF file reportno
polaris_upload_sarif_reportFlag to enable/disable uploading of Polaris SARIF report to GitHub Advanced Securityno
polaris_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
polaris_assessment_modeThe test mode type of this scanno
project_directoryThe project source directory. Defaults to repository root directory. Set this to specify a custom folder that is other than repository rootno
project_source_archiveThe zipped source file path. It overrides the project directory settingno
project_source_preserveSymLinksFlag indicating whether to preserve symlinks in the source zipno
project_source_excludesA list of git ignore pattern strings that indicate the files need to be excluded from the zip fileno
synopsys_bridge_install_directorySynopsys Bridge Install Directoryno
synopsys_bridge_download_urlURL to download bridge fromno
blackduck_urlURL for blackduck hubno
blackduck_tokenAPI token to access blackduckno
blackduck_install_directoryDirectory to find or install detectno
blackduck_scan_fullScan Mode. (true for intelligent scan & false for rapid scan)no
blackduck_scan_failure_severitiesIf provided, Blackduck will break the build if any issues produced match one of the given severitiesno
blackduck_automation_fixprIf set as true, separate Fix PRs will be created if vulnerability is found after scanno
blackduck_fixpr_enabledFlag to enable/disable the automatic fix pull request creations for Black Duckno
blackduck_fixpr_maxCountMaximum number of Pull Requests to be created that violate policiesno
blackduck_fixpr_filter_severitiesIf provided, Fix PRs will be created only for given severitiesno
blackduck_fixpr_useUpgradeGuidanceFlag to enable long term upgrade guidanceno
synopsys_bridge_download_versionIf provided, Synopsys-action will configure the version of Bridgeno
blackduck_prComment_enabledFlag to enable pull request comments for new issues found in the Black Duck scanno
blackduck_reports_sarif_createFlag to enable/disable Black Duck SARIF report generationno
blackduck_reports_sarif_file_pathFile path including file name where Black Duck SARIF report should be createdno
blackduck_reports_sarif_severitiesIndicates what SAST/SCA issues severity categories to include in Black Duck SARIF file reportno
blackduck_reports_sarif_groupSCAIssuesFlag to enable/disable Component-Version grouping for SCA Issues in Black Duck SARIF report rules sectionno
blackduck_upload_sarif_reportFlag to enable/disable uploading of Black Duck SARIF report to GitHub Advanced Securityno
blackduck_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
blackduck_search_depthNumber indicating the search depth in the source directoryno
blackduck_argsAdditional Black Duck Arguments separated by spaceno
blackduck_config_pathBlack Duck config file path (.properties/.yml)no
blackduck_policy_badges_createTo enable creation of badges on the GitHub repositoryno
blackduck_policy_badges_maxCountTo limit number of badges to be displayed on the GitHub repositoryno
srm_urlSRM Urlno
srm_apikeySRM Api Keyno
srm_assessment_typesSRM Assessment Typesno
srm_project_nameSRM project nameno
srm_branch_nameSRM branch nameno
srm_project_idSRM branch Idno
srm_branch_parentSRM branch parentno
srm_waitForScanSpecifies if the workflow should wait for the analysis to complete. Default value: true. If set to false, post merge workflows like PR comment, Fix PR, SARIF etc will not be applicable.no
coverity_execution_pathCoverity execution pathno
blackduck_execution_pathBlack Duck execution pathno
github_tokenGithub token to be used for git related rest operationno
include_diagnosticsTo include diagnostics info and export as zipno
diagnostics_retention_daysNumber of days to keep the diagnostics files downloadableno
bridge_network_airgapIf provided, Synopsys Action will be using local network to download and execute bridge .no
network_airgapIf provided, Synopsys Action will be using local network to download and execute bridge .no

no outputs