Balam Forgejo action
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
James Luther cf9d354832
All checks were successful
test / test (push) Successful in 5s
security-scan / security-scan (push) Successful in 24s
Merge pull request 'fix: revert security-scan.yml to inline, not a reusable-workflow call' (#8) from fix/inline-security-scan into main
Reviewed-on: #8
2026-09-07 20:10:16 +00:00
.forgejo/workflows fix: revert security-scan.yml to inline, not a reusable-workflow call 2026-09-07 15:03:56 -05:00
test Initial commit: balam upload action 2026-09-03 16:19:09 -05:00
.gitignore Gitignore .semgrep/ (local guardian tool state, not part of the project) 2026-09-04 14:15:32 -05:00
action.yml Initial commit: balam upload action 2026-09-03 16:19:09 -05:00
LICENSE Initial commit: balam upload action 2026-09-03 16:19:09 -05:00
README.md Initial commit: balam upload action 2026-09-03 16:19:09 -05:00
renovate.json ci: add Renovate for automated dependency updates 2026-09-06 12:56:08 -05:00
upload.sh Initial commit: balam upload action 2026-09-03 16:19:09 -05:00

balam-forgejo

Forgejo/Gitea Action that uploads a scan report (Trivy, Semgrep, SARIF, ojo, or any format Balam parses) to Balam via reimport-scan. Nothing else — run your scanner first, then point this at the report it produced. Identical in behavior to balam-action (its GitHub counterpart); this is a separate repo only because Forgejo instances typically can't pull actions from github.com.

Usage

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      # ... run your scanner, produce report.json ...
      - uses: colibrisec/balam-forgejo@v1
        with:
          file: report.json
          scan-type: 'Trivy Scan'
          balam-url: https://balam.example.com
          balam-token: ${{ secrets.BALAM_TOKEN }}
          product-name: my-app
          engagement-name: main

Mint balam-token as a personal API token in Balam and store it as a repo/org secret.

Inputs

Input Required Notes
file yes Path to the report to upload
scan-type yes Balam scan_type, e.g. Trivy Scan, Semgrep JSON Report, SARIF, OJO Scan — see Balam's supported parsers
balam-url yes Balam base URL
balam-token yes Balam personal API token — pass via a secret
product-name / product-id one of Name auto-creates the product
engagement-name / engagement-id one of Name auto-creates the engagement
product-type-name no
test-title no

Development

$ bash test/test_upload.sh

Support

☕ Buy me a coffee

License

GPL-2.0, matching Balam's own license.