Forgejo action for Ojo
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
James Luther f24fd392ef
All checks were successful
test / test (push) Successful in 12s
security-scan / security-scan (push) Successful in 1m17s
Merge pull request 'fix: revert security-scan.yml to inline, not a reusable-workflow call' (#17) from fix/inline-security-scan into main
Reviewed-on: #17
2026-09-07 20:10:00 +00:00
.forgejo/workflows
test
.gitignore
action.yml
LICENSE
README.md
renovate.json
scan.sh

ojo-forgejo

Buy Me a Coffee

Forgejo/Gitea Action that runs ojo (dependency, secret, IaC, SAST, and code-quality scanning), publishes the reports as a workflow artifact, and on pull_request/pull_request_target events posts (and keeps updated) a findings summary comment on the PR. Requires a runner with Docker access.

Pair with balam-forgejo later in the pipeline to upload the reports to Balam.

Usage

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: colibrisec/ojo-forgejo@v1
      # - uses: colibrisec/balam-forgejo@v1
      #   with:
      #     balam-url: https://balam.example.com
      #     balam-token: ${{ secrets.BALAM_TOKEN }}

Inputs

Input Default Notes
vulnerabilities true Dependency CVEs (ojo vuln)
secrets true Hardcoded credentials (ojo secret)
iac true Dockerfile/Kubernetes/Terraform misconfig (ojo misconfig)
sast true Source-level issues (ojo sast)
quality false Maintainability smells (ojo quality), off by default same as ojo itself
sbom false CycloneDX SBOM, published as a workflow artifact
ojo-version latest Tag of ghcr.io/colibrisec/ojo
path . Path to scan, relative to the repo root
image Container image ref to scan for vulnerable OS packages (ojo image); empty skips it
fail-on-findings false true fails the job when ojo finds anything
upload-artifact true Publish ojo-report.json/ojo-image-report.json/ojo-sbom.cdx.json as a workflow artifact
pr-comment true Post/update a findings summary comment on the triggering PR (needs a token with issue/PR write access)
token ${{ github.token }} Used for the PR comment

License

GPL-2.0, matching ojo's own license.