{"repo":"google/osv-scanner-action","free":true,"listed":false,"github":"https://github.com/google/osv-scanner-action","clone":"git clone https://github.com/google/osv-scanner-action.git","description":null,"language":"Python","stars":94,"topics":["github-actions","osv","vulnerability-scanners"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"OSV-Scanner CI/CD Action The OSV-Scanner CI/CD action leverages the OSV.dev database and the OSV-Scanner CLI tool to track and notify you of known vulnerabilities in your dependencies for over 11 languages and ecosystems. We currently offer two different reusable workflows for Github: 1. A workflow that triggers a scan with each pull request and will only report new vulnerabilities introduced through the pull request. 2. A workflow that performs a full vulnerability scan, which can be configured to scan on pushes or a regular schedule. The full vulnerability scan can also be configured to run on release to prevent releasing with known vulnerabilities in dependencies. Currently there is no prebuilt workflows for other platforms, but we welcome any contributions for this! Scheduled scan Regularly scanning your project for vulnerabilities can alert you to new vulnerabilities in your dependency tree. The scheduled scan will scan your project on a set schedule or when a new commit is pushed, and report all known vulnerabilities. If vulnerabilities are found it will be reported to the \"Code scanning\" page. OSV-Scanner Code Scanning Results Code Scanning Detailed Entry :------------------------------------------------------------------------------: :-------------------------------------------------------------------------------------------: Scan on pull request Scanning your project on each pull request can help you keep vulnerabilities out of your project. The pull request scan com","default_branch":null,"files":null,"tree":[],"storefront":"/r/google","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/google/osv-scanner-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}