Forgejo action for Ojo
- Shell 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
|
||
| .forgejo/workflows | ||
| test | ||
| .gitignore | ||
| action.yml | ||
| LICENSE | ||
| README.md | ||
| renovate.json | ||
| scan.sh | ||
ojo-forgejo
Forgejo/Gitea Action that runs ojo (dependency,
secret, IaC, SAST, and code-quality scanning), publishes the reports as a workflow
artifact, and on pull_request/pull_request_target events posts (and keeps updated)
a findings summary comment on the PR. Requires a runner with Docker access.
Pair with balam-forgejo later in the
pipeline to upload the reports to Balam.
Usage
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: colibrisec/ojo-forgejo@v1
# - uses: colibrisec/balam-forgejo@v1
# with:
# balam-url: https://balam.example.com
# balam-token: ${{ secrets.BALAM_TOKEN }}
Inputs
| Input | Default | Notes |
|---|---|---|
vulnerabilities |
true |
Dependency CVEs (ojo vuln) |
secrets |
true |
Hardcoded credentials (ojo secret) |
iac |
true |
Dockerfile/Kubernetes/Terraform misconfig (ojo misconfig) |
sast |
true |
Source-level issues (ojo sast) |
quality |
false |
Maintainability smells (ojo quality), off by default same as ojo itself |
sbom |
false |
CycloneDX SBOM, published as a workflow artifact |
ojo-version |
latest |
Tag of ghcr.io/colibrisec/ojo |
path |
. |
Path to scan, relative to the repo root |
image |
Container image ref to scan for vulnerable OS packages (ojo image); empty skips it |
|
fail-on-findings |
false |
true fails the job when ojo finds anything |
upload-artifact |
true |
Publish ojo-report.json/ojo-image-report.json/ojo-sbom.cdx.json as a workflow artifact |
pr-comment |
true |
Post/update a findings summary comment on the triggering PR (needs a token with issue/PR write access) |
token |
${{ github.token }} |
Used for the PR comment |
License
GPL-2.0, matching ojo's own license.