yakohhhh/Portcullis security scan

Audit a self-hosted stack's docker-compose exposure and foot-guns, publish a report to the job summary, and fail the job above a severity threshold.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to scan (a compose file or a directory tree).no.
fail-onFail the job if any finding is at or above this severity (critical | high | medium | low | info | never).nohigh
min-severityHide findings below this severity in the report.noinfo
trivyRun Trivy too, when the binary is available (true | false).nofalse
comment-on-prPost the report as a pull-request comment (true | false). Requires the job to grant `pull-requests: write`.nofalse
python-versionPython version used to run Portcullis.no3.12
namedescription
gradeOverall grade, A-F.
scoreOverall score, 0-100.