zien-tf/Z-BOM SBOM Checker

Submit source to your on-premises Z-BOM service for SBOM/CVE analysis and report results on the PR.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
urlZ-BOM server URL (e.g. http://z-bom:8000)yes
web-urlZ-BOM web UI base for the report link (defaults to url)no""
tokenZ-BOM CI token (store as the Z_BOM_TOKEN secret)yes
typeScan type: code | firmwarenocode
pathSource path to archive (git-tracked files under this path)no.
waitWait for the scan to finish and report resultsnotrue
timeoutMax seconds to wait for completionno1800
poll-intervalSeconds between status pollsno10
fail-onFail the job if a CVE of this severity or higher is found: critical | high | medium | low | nonenonone
commentUpsert a PR comment with the resultnotrue
github-tokenToken used to post the PR commentno${{ github.token }}
namedescription
run-idZ-BOM analysis run id
statusFinal run status (COMPLETED | FAILED | ...)
total-cveNumber of CVEs needing response
result-jsonFull result summary JSON