GitHub Action
Run a Vulnara scan from a GitHub workflow and fail the job when a finding reaches the severity you choose.
Build your workflow
Pick your options and copy the file into .github/workflows/. Credentials stay in GitHub secrets and variables.
.github/workflows/vulnara.yml
name: Vulnara Scan
on:
push:
branches: [main]
pull_request:
jobs:
vulnara:
runs-on: ubuntu-latest
steps:
- uses: theorigamicorporation/vulnara-action@v1
id: vulnara
with:
service-account: ${{ vars.VULNARA_SERVICE_ACCOUNT }}
token: ${{ secrets.VULNARA_TOKEN }}
tenant: ${{ vars.VULNARA_TENANT }}
scan-tools: '11111111-2222-3333-4444-555555555555'
fail-on: critical
- run: echo "Highest severity ${{ steps.vulnara.outputs.highest-severity }}"
if: always()
Add VULNARA_TOKEN as a secret, and VULNARA_SERVICE_ACCOUNT and VULNARA_TENANT as variables, in the repository settings.
Inputs
| Name | Description |
|---|---|
| service-accountRequired | Vulnara service account username. |
| tokenRequired | Vulnara service account token (password). Store it as a GitHub secret. |
| tenantRequired | Vulnara tenant (workspace) id the service account belongs to. |
| scan-toolsRequired | Comma-separated scan tool names or ids to run (e.g. "AEGIS,pdd"). |
| branch | Branch to scan. Defaults to the branch that triggered the workflow. |
| repository | owner/name of the repository to scan in Vulnara. Defaults to the current GitHub repository. |
| git-token-id | Vulnara git token id to use for cloning (required for private repositories). |
| fail-on | Fail the job if a finding at or above this severity is found: none | low | medium | high | critical.Default: critical |
| create-issue | Create an issue in the repository for findings.Default: false |
| auto-remediate | Open a fix pull request for findings (requires create-issue).Default: false |
| wait-timeout | Max seconds to wait for the scan(s) to finish before failing.Default: 1800 |
| poll-interval | Seconds between scan status checks.Default: 15 |
| app-url | Vulnara web app base URL, used to build links to scans in the platform (override for non-prod).Default: https://vulnara.rso.dev |
| gateway-url | Vulnara GraphQL gateway URL (override for non-prod).Default: https://vulnara-gw.rso.dev/graphql |
| token-url | OAuth token endpoint (override for non-prod).Default: https://auth.theorigamicorporation.com/application/o/token/ |
| oauth-client-id | OAuth client id used for the service-account token exchange (override for non-prod).Default: hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4 |
Outputs
| Name | Description |
|---|---|
| scan-result-ids | Space-separated ids of the scan results that were started. |
| highest-severity | The highest finding severity discovered across the scans (or "none"). |
| passed | "true" if the scans passed the fail-on gate, "false" otherwise. |