- name: Scan for vulnerabilities uses: crazy-max/ghaction-container-scan@v3
- name: Scan for vulnerabilities uses: crazy-max/ghaction-container-scan@v3
- name: Scan for vulnerabilities uses: crazy-max/ghaction-container-scan@v3
# Install
go install github.com/julietsecurity/abom@latest # Generate an ABOM for your repo
abom scan . # Check against known-compromised actions
abom scan . --check # Export as CycloneDX
abom scan . -o cyclonedx-json
# Install
go install github.com/julietsecurity/abom@latest # Generate an ABOM for your repo
abom scan . # Check against known-compromised actions
abom scan . --check # Export as CycloneDX
abom scan . -o cyclonedx-json
# Install
go install github.com/julietsecurity/abom@latest # Generate an ABOM for your repo
abom scan . # Check against known-compromised actions
abom scan . --check # Export as CycloneDX
abom scan . -o cyclonedx-json - CycloneDX 1.5 — actions become components, transitive relationships go in the dependency graph, compromised actions show up as vulnerabilities. Plugs directly into Dependency-Track, Grype, and other tooling.
- SPDX 2.3 — actions become packages with DEPENDS_ON relationships. Works with existing license compliance and SBOM aggregation tools.