{"repo":"oss-review-toolkit/ort-ci-github-action","free":true,"listed":false,"github":"https://github.com/oss-review-toolkit/ort-ci-github-action","clone":"git clone https://github.com/oss-review-toolkit/ort-ci-github-action.git","description":"Run ORT in your GitHub action workflow to do licensing, security and best practices checks and generate reports/SBOMs","language":null,"stars":34,"topics":["actions","cyclonedx","github-action","github-actions","license-checking","sbom","sbom-generator","spdx","ospo","ci"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"GitHub Action for ORT Run licensing, security, best practices checks and generate reports/Software Bill of Materials (SBOMs) using [ORT][ort] within [GitHub Actions][gh-action-docs]. Usage See action.yml Note: All examples below use the main branch. When implementing the GitHub Action for ORT in production, it's recommended to use the latest [tags][ort-gh-action-tags]. Basic Alternatively, you can also use ORT to download the project sources using Git, Git-repo, Mercurial or Subversion. Scenarios - Run ORT and analyze only specified package managers - Run ORT with labels - Run ORT and fail job on policy violations or security issues - Run ORT on private repositories - Run ORT on multiple repositories using a matrix - Run ORT with a custom global configuration - Run ORT with a custom Docker image - Run ORT with PostgreSQL database - Run only parts of the GitHub Action for ORT Run ORT and analyze only specified package managers Run ORT with labels Use labels to track scan related info or execute policy rules for specific product, delivery or organization. Run ORT and fail job on policy violations or security issues Set fail-on to fail the action if: - policy violations reported by Evaluator exceed the severeRuleViolationThreshold level. - security issues reported by the Advisor exceed the severeIssueThreshold level. By default severeRuleViolationThreshold and severeIssueThreshold are set to WARNING but you can change this to for example ERROR in your [config.yml][ort-config-yml","default_branch":null,"files":null,"tree":[],"storefront":"/r/oss-review-toolkit","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/oss-review-toolkit/ort-ci-github-action/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}