{"repo":"anchore/scan-action","free":true,"listed":false,"github":"https://github.com/anchore/scan-action","clone":"git clone https://github.com/anchore/scan-action.git","description":"Anchore container analysis and scan provided as a GitHub Action","language":"JavaScript","stars":286,"topics":["vulnerabilities","workflow","actions","github-actions","policy-evaluation","anchore-engine"],"license":"MIT","category":"workflow-automation","readme_excerpt":"GitHub Action for Vulnerability Scanning :zap: Find threats in files or containers at lightning speed :zap: [![Test Status][test-img]][test] This is a GitHub Action for invoking the Grype scanner and returning the vulnerabilities found, and optionally fail if a vulnerability is found with a configurable severity level. Use this in your workflows to quickly verify files or containers' content after a build and before pushing, allowing PRs, or deploying updates. The action invokes the grype command-line tool, with these benefits: - Runs locally, without sending data outbound - no credentials required! - Speedy scan operations - Scans both paths and container images - Easy failure evaluation depending on vulnerability severity The example workflows have lots of usage examples for scanning both containers and directories. By default, a scan will produce very detailed output on system packages like an RPM or DEB, but also language-based packages. These are some of the supported packages and libraries: Supported Linux Distributions: - Alpine - BusyBox - CentOS and RedHat - Debian and Debian-based distros like Ubuntu Supported packages and libraries: - Ruby Bundles - Python Wheel, Egg, requirements.txt - JavaScript NPM/Yarn - Java JAR/EAR/WAR, Jenkins plugins JPI/HPI - Go modules [!TIP] Security best practice : For production workflows, pin actions to a full commit SHA rather than a version tag. You can find the latest SHA for each release on the action's releases page. Container sc","default_branch":null,"files":null,"tree":[],"storefront":"/r/anchore","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/anchore/scan-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}