GitHub Action
Starte einen Vulnara-Scan aus einem GitHub-Workflow und lass den Job scheitern, wenn ein Befund die gewählte Schwere erreicht.
Workflow zusammenstellen
Wähle deine Optionen und kopiere die Datei nach .github/workflows/. Zugangsdaten bleiben in GitHub-Secrets und -Variablen.
.github/workflows/vulnara.yml
name: Vulnara Scan
on:
push:
branches: [main]
pull_request:
jobs:
vulnara:
runs-on: ubuntu-latest
steps:
- uses: theorigamicorporation/vulnara-action@v1
id: vulnara
with:
service-account: ${{ vars.VULNARA_SERVICE_ACCOUNT }}
token: ${{ secrets.VULNARA_TOKEN }}
tenant: ${{ vars.VULNARA_TENANT }}
scan-tools: '11111111-2222-3333-4444-555555555555'
fail-on: critical
- run: echo "Highest severity ${{ steps.vulnara.outputs.highest-severity }}"
if: always()
Lege in den Repository-Einstellungen VULNARA_TOKEN als Secret sowie VULNARA_SERVICE_ACCOUNT und VULNARA_TENANT als Variablen an.
Eingaben
| Name | Beschreibung |
|---|---|
| service-accountPflicht | Vulnara service account username. |
| tokenPflicht | Vulnara service account token (password). Store it as a GitHub secret. |
| tenantPflicht | Vulnara tenant (workspace) id the service account belongs to. |
| scan-toolsPflicht | Comma-separated scan tool names or ids to run (e.g. "AEGIS,pdd"). |
| branch | Branch to scan. Defaults to the branch that triggered the workflow. |
| repository | owner/name of the repository to scan in Vulnara. Defaults to the current GitHub repository. |
| git-token-id | Vulnara git token id to use for cloning (required for private repositories). |
| fail-on | Fail the job if a finding at or above this severity is found: none | low | medium | high | critical.Standard: critical |
| create-issue | Create an issue in the repository for findings.Standard: false |
| auto-remediate | Open a fix pull request for findings (requires create-issue).Standard: false |
| wait-timeout | Max seconds to wait for the scan(s) to finish before failing.Standard: 1800 |
| poll-interval | Seconds between scan status checks.Standard: 15 |
| app-url | Vulnara web app base URL, used to build links to scans in the platform (override for non-prod).Standard: https://vulnara.rso.dev |
| gateway-url | Vulnara GraphQL gateway URL (override for non-prod).Standard: https://vulnara-gw.rso.dev/graphql |
| token-url | OAuth token endpoint (override for non-prod).Standard: https://auth.theorigamicorporation.com/application/o/token/ |
| oauth-client-id | OAuth client id used for the service-account token exchange (override for non-prod).Standard: hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4 |
Ausgaben
| Name | Beschreibung |
|---|---|
| scan-result-ids | Space-separated ids of the scan results that were started. |
| highest-severity | The highest finding severity discovered across the scans (or "none"). |
| passed | "true" if the scans passed the fail-on gate, "false" otherwise. |