{"repo":"kubescape/github-action","free":true,"listed":false,"github":"https://github.com/kubescape/github-action","clone":"git clone https://github.com/kubescape/github-action.git","description":"GitHub action to run Kubescape scans","language":"Shell","stars":24,"topics":["github-actions","kubernetes-security","kubescape"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Kubescape action Run security scans on your Kubernetes manifests and Helm charts as a part of your CI using the Kubescape action. Kubescape scans Kubernetes clusters, YAML files, and HELM charts, detecting misconfigurations according to multiple frameworks (such as the NSA-CISA , MITRE ATT&CK® and CIS Benchmark), software vulnerabilities. Usage Scanning with Kubescape To scan your repository with Kubescape in your Github workflow, add the following steps to your workflow configuration: This workflow definition scans your repository with Kubescape and publishes the results to Github. You can then see the results in the Pull Request that triggered the scan and the Security → Code scanning tab. Automatically Suggest Fixes To make Kubescape automatically suggest fixes to your pull requests by code review, use the following workflow: The above workflow works by collecting the SARIF (Static Analysis Results Interchange Format) file that kubescape generates. Then, with the help of HollowMan6/sarif4reviewdog, convert the SARIF file into RDFormat (Reviewdog Diagnostic Format) and generate reviews using Reviewdog. You can also make Kubescape automatically suggest fixes for the pushes to your main branch by opening new PRs with the following workflow: The above workflow works by collecting the changes made directly to the original files. In the example above, a separate step that runs a different action opens the appropriate pull request. Due to how Github works, there are limitations o","default_branch":null,"files":null,"tree":[],"storefront":"/r/kubescape","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kubescape/github-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}