Skip to content

GitHub Action to perform a docker scan with VMWARE tern

License

Notifications You must be signed in to change notification settings

philips-labs/tern-action

Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

45 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

GitHub Action to VMWARE's tern!

Marketplace Release .github/workflows/lint.yml

This Action wraps tern allowing scanning of your docker images!

Contents

Inputs

image

Required docker image to scan. Example: alpine:latest

format

Output format. Can be either: json, html, spdxtagvalue, spdxjson, yaml or human

Optional defaults to json

output

Optional Name of the output file. Defaults to tern.<format>

Outputs

output

output JSON string

file

output JSON file.

Environment Variables

Example Usage

Vanilla

tern CLI will automatically scan your image`:

name: build 
on: [push]

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: philips-labs/[email protected]
        id: scan
        with:
          image: alpine:latest
          format: yaml
          output: alpine.yaml
      - uses: actions/upload-artifact@v2
        with:
          name: tern 
          path: ${{ steps.scan.outputs.file }} 

Examples

example repo

Contributors

Thanks goes to these contributors!

License

MIT License

About

GitHub Action to perform a docker scan with VMWARE tern

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Contributors 3

  •  
  •  
  •