{"repo":"advanced-security/component-detection-dependency-submission-action","free":true,"listed":false,"github":"https://github.com/advanced-security/component-detection-dependency-submission-action","clone":"git clone https://github.com/advanced-security/component-detection-dependency-submission-action.git","description":"This GitHub Action runs the microsoft/component-detection library to automate dependency extraction at build time.","language":"TypeScript","stars":25,"topics":["github-actions","dependency-submission"],"license":"MIT","category":"workflow-automation","readme_excerpt":"Component detection dependency submission action This GitHub Action runs the microsoft/component-detection library to automate dependency extraction at build time. It uses a combination of static and dynamic scanning to build a dependency tree and then uploads that to GitHub's dependency graph via the dependency submission API. This gives you more accurate Dependabot alerts, and support for a bunch of additional ecosystems. Example workflows Additional Experimental and DefaultOff detectors: - For a list of experimental and default-off detectors that require explicit enablement, see the Detectors README. See enable-default-off.md for more details. Configuration options Parameter Description Example --- --- --- filePath The path to the directory containing the environment files to upload. Defaults to Actions working directory. '.' directoryExclusionList Filters out specific directories following a minimatch pattern. test detectorArgs Comma separated list of properties that can affect the detectors execution, like EnableIfDefaultOff that allows a specific detector that is Experimental or DefaultOff to run, the format for this property is DetectorId=EnableIfDefaultOff, for example Pip=EnableIfDefaultOff. Pip=EnableIfDefaultOff dockerImagesToScan Comma separated list of docker image names or hashes to execute container scanning on ubuntu:16.04,56bab49eef2ef07505f6a1b0d5bd3a601dfc3c76ad4460f24c91d6fa298369ab detectorsFilter A comma separated list with the identifiers of the specifi","default_branch":null,"files":null,"tree":[],"storefront":"/r/advanced-security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/advanced-security/component-detection-dependency-submission-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}