xkobxx/DevSecOps Trust Gate
Run Bandit, Semgrep, pip-audit, Trivy and Gitleaks against any repo, aggregate findings into one gate and dashboard.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| target | Path to scan, relative to the repo root | no | . |
| fail-on | Minimum severity that fails the gate: critical | high | medium | low | none | no | high |
| license-key | Paid license key. Unlocks confidence scoring (empirical precision per finding, ranked "act on these first" triage). Free tier runs fine without one. | no | "" |
Outputs
| name | description |
|---|---|
| findings-path | Path to the unified findings.json produced by this run |