Zum Hauptinhalt springen

GitHub Action

Starte einen Vulnara-Scan aus einem GitHub-Workflow und lass den Job scheitern, wenn ein Befund die gewählte Schwere erreicht.

Workflow zusammenstellen

Wähle deine Optionen und kopiere die Datei nach .github/workflows/. Zugangsdaten bleiben in GitHub-Secrets und -Variablen.

.github/workflows/vulnara.yml
name: Vulnara Scan
on:
  push:
    branches: [main]
  pull_request:

jobs:
  vulnara:
    runs-on: ubuntu-latest
    steps:
      - uses: theorigamicorporation/vulnara-action@v1
        id: vulnara
        with:
          service-account: ${{ vars.VULNARA_SERVICE_ACCOUNT }}
          token: ${{ secrets.VULNARA_TOKEN }}
          tenant: ${{ vars.VULNARA_TENANT }}
          scan-tools: '11111111-2222-3333-4444-555555555555'
          fail-on: critical
      - run: echo "Highest severity ${{ steps.vulnara.outputs.highest-severity }}"
        if: always()

Lege in den Repository-Einstellungen VULNARA_TOKEN als Secret sowie VULNARA_SERVICE_ACCOUNT und VULNARA_TENANT als Variablen an.

Eingaben

NameBeschreibung
service-accountPflichtVulnara service account username.
tokenPflichtVulnara service account token (password). Store it as a GitHub secret.
tenantPflichtVulnara tenant (workspace) id the service account belongs to.
scan-toolsPflichtComma-separated scan tool names or ids to run (e.g. "AEGIS,pdd").
branchBranch to scan. Defaults to the branch that triggered the workflow.
repositoryowner/name of the repository to scan in Vulnara. Defaults to the current GitHub repository.
git-token-idVulnara git token id to use for cloning (required for private repositories).
fail-onFail the job if a finding at or above this severity is found: none | low | medium | high | critical.Standard: critical
create-issueCreate an issue in the repository for findings.Standard: false
auto-remediateOpen a fix pull request for findings (requires create-issue).Standard: false
wait-timeoutMax seconds to wait for the scan(s) to finish before failing.Standard: 1800
poll-intervalSeconds between scan status checks.Standard: 15
app-urlVulnara web app base URL, used to build links to scans in the platform (override for non-prod).Standard: https://vulnara.rso.dev
gateway-urlVulnara GraphQL gateway URL (override for non-prod).Standard: https://vulnara-gw.rso.dev/graphql
token-urlOAuth token endpoint (override for non-prod).Standard: https://auth.theorigamicorporation.com/application/o/token/
oauth-client-idOAuth client id used for the service-account token exchange (override for non-prod).Standard: hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4

Ausgaben

NameBeschreibung
scan-result-idsSpace-separated ids of the scan results that were started.
highest-severityThe highest finding severity discovered across the scans (or "none").
passed"true" if the scans passed the fail-on gate, "false" otherwise.

Verwalten Sie Ihre Cookie-Einstellungen

Wir verwenden Cookies, um Ihr Erlebnis zu verbessern. Sie können alle Cookies akzeptieren, nicht unbedingt erforderliche Cookies ablehnen oder unten Ihre Einstellungen verwalten. Datenschutzerklärung