-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathaction.yml
More file actions
61 lines (47 loc) · 1.55 KB
/
Copy pathaction.yml
File metadata and controls
61 lines (47 loc) · 1.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
name: DevShield Security Scan
description: Developer-first GitHub Action for security scanning, SARIF reporting, deployment protection, and AI-powered analysis.
author: DevShield
branding:
icon: shield
color: blue
inputs:
required-paths:
description: "Comma-separated list of files or directories that must exist before scanning."
required: false
default: "package.json"
node-version:
description: "Node.js version used to run DevShield."
required: false
default: "24"
devshield-api-key:
description: "DevShield project API key."
required: true
devshield-api-url:
description: "DevShield API endpoint."
required: false
default: "https://devshield.site/api/analyze"
outputs:
passed:
description: "Whether the security scan passed."
report:
description: "Path to the generated DevShield report."
runs:
using: composite
steps:
- name: Checkout Repository
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: ${{ inputs.node-version }}
- name: Install Dependencies
shell: bash
working-directory: ${{ github.action_path }}
run: npm install
- name: Run DevShield Security Scan
shell: bash
working-directory: ${{ github.workspace }}
env:
DEVSHIELD_API_KEY: ${{ inputs.devshield-api-key }}
DEVSHIELD_API_URL: ${{ inputs.devshield-api-url }}
run: node "${{ github.action_path }}/api/github-action-scan.js"