{"repo":"bridgecrewio/bridgecrew-action","free":true,"listed":false,"github":"https://github.com/bridgecrewio/bridgecrew-action","clone":"git clone https://github.com/bridgecrewio/bridgecrew-action.git","description":"This GitHub Action runs Bridgecrew against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.","language":null,"stars":73,"topics":["static-analysis","github","actions","github-actions","bridgecrew","marketplace","compliance","devsecops","scanning","security"],"license":"MIT","category":"security-tools","readme_excerpt":"DEPRECATED: This project is no longer supported and will be archived end of 2023. Please use checkov-action instead. Bridgecrew GitHub Action The Bridgecrew GitHub Action Use the Bridgecrew GitHub Action to scan for infrastructure-as-code misconfigurations, vulnerabilities and license issues in open source packages and images, and CI/CD misconfigurations. By signing up for a free Bridgecrew Community plan you can also view dashboards and reports. The community plan does not limit the number of scans or users you can invite to view the results. How to use the Bridgecrew GitHub Action 1. Follow the instructions at GitHub configuration a workflow to enable Github Action in your repository. 2. Set up an environment variable with your Bridgecrew API key, which you can get from your Bridgecrew account. 3. In the app build job, uses the bridgecrewio/bridgecrew-action@master 4. Optionally, supply parameters to customize GitHub action behaviour Usage Examples Scan IaC in your repository Github code scanning Bridgecrew supports github code scanning. An example workflow configuration can be found here. GitHub action Parameters Parameter Description Required Default Type ------------------------------- -------------------------------------------------------------------------------------------------------------------------------------------------------------- ---------- --------- ----------------------------------------- api-key Environment variable name of the Bridgecrew API key from Bri","default_branch":null,"files":null,"tree":[],"storefront":"/r/bridgecrewio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bridgecrewio/bridgecrew-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}