Skip to main content

GitHub Action

Run a Vulnara scan from a GitHub workflow and fail the job when a finding reaches the severity you choose.

Build your workflow

Pick your options and copy the file into .github/workflows/. Credentials stay in GitHub secrets and variables.

.github/workflows/vulnara.yml
name: Vulnara Scan
on:
  push:
    branches: [main]
  pull_request:

jobs:
  vulnara:
    runs-on: ubuntu-latest
    steps:
      - uses: theorigamicorporation/vulnara-action@v1
        id: vulnara
        with:
          service-account: ${{ vars.VULNARA_SERVICE_ACCOUNT }}
          token: ${{ secrets.VULNARA_TOKEN }}
          tenant: ${{ vars.VULNARA_TENANT }}
          scan-tools: '11111111-2222-3333-4444-555555555555'
          fail-on: critical
      - run: echo "Highest severity ${{ steps.vulnara.outputs.highest-severity }}"
        if: always()

Add VULNARA_TOKEN as a secret, and VULNARA_SERVICE_ACCOUNT and VULNARA_TENANT as variables, in the repository settings.

Inputs

NameDescription
service-accountRequiredVulnara service account username.
tokenRequiredVulnara service account token (password). Store it as a GitHub secret.
tenantRequiredVulnara tenant (workspace) id the service account belongs to.
scan-toolsRequiredComma-separated scan tool names or ids to run (e.g. "AEGIS,pdd").
branchBranch to scan. Defaults to the branch that triggered the workflow.
repositoryowner/name of the repository to scan in Vulnara. Defaults to the current GitHub repository.
git-token-idVulnara git token id to use for cloning (required for private repositories).
fail-onFail the job if a finding at or above this severity is found: none | low | medium | high | critical.Default: critical
create-issueCreate an issue in the repository for findings.Default: false
auto-remediateOpen a fix pull request for findings (requires create-issue).Default: false
wait-timeoutMax seconds to wait for the scan(s) to finish before failing.Default: 1800
poll-intervalSeconds between scan status checks.Default: 15
app-urlVulnara web app base URL, used to build links to scans in the platform (override for non-prod).Default: https://vulnara.rso.dev
gateway-urlVulnara GraphQL gateway URL (override for non-prod).Default: https://vulnara-gw.rso.dev/graphql
token-urlOAuth token endpoint (override for non-prod).Default: https://auth.theorigamicorporation.com/application/o/token/
oauth-client-idOAuth client id used for the service-account token exchange (override for non-prod).Default: hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4

Outputs

NameDescription
scan-result-idsSpace-separated ids of the scan results that were started.
highest-severityThe highest finding severity discovered across the scans (or "none").
passed"true" if the scans passed the fail-on gate, "false" otherwise.

Manage Your Cookie Preferences

We use cookies to enhance your experience. You can accept all cookies, decline non-essential cookies, or manage preferences below. Privacy Policy