ProdgatorDocs
SecurityUpload reports

Upload from GitHub Actions

Attach scanner output to a run report with the Prodgator report action, with no API key.

Availability

Team plan and above. Uploading needs the or role, or a custom role with .

From GitHub Actions

The Prodgator report action can attach a scanner's output file to a or attestation. When that file is SARIF, CycloneDX or SPDX JSON and uploads with the report, Prodgator reads it into findings as well, with no API key. Set up a scanner has an example for each common scanner:

permissions:
  id-token: write

steps:
  - run: trivy fs --format sarif --output trivy-results.sarif .
  - uses: prodgator/prodgator-action@v1
    if: always()
    with:
      attestations: |
        [{ "kind": "scan", "name": "trivy", "file": "trivy-results.sarif", "format": "sarif", "data": { "tool": "trivy", "failOn": "high" } }]
  • The attestation's becomes the upload's category (characters outside the category alphabet become ).
  • The repository, ref and commit come from the run's GitHub OIDC token.
  • is optional: (default) or . A diff scan looks only at changed code, so Prodgator never uses it to close findings or to confirm or clear findings carried over from pull requests. Any other value is ignored with a warning.
  • Reports from a fork, or are marked untrusted. Their scan results are kept in the Scan results view but never open findings.
  • These uploads count against the run's limit, not the hourly limit. A report over the limit is still stored as a run report; only its findings are skipped.
  • The action also accepts and for compatibility. Those files are attached to the run report, but Prodgator reads no findings from them. Use .

Scan the tracked branch too

Run the same step on pushes to your tracked branch and on a schedule, as well as on pull requests. Findings from a merged pull request wait for a scan of the tracked branch to confirm or clear them. See Findings from pull requests for a workflow.

Several scanners in one step

One action step can send several files. Put every attestation in the same array:

      - uses: prodgator/prodgator-action@v1
        if: always()
        with:
          attestations: |
            [
              { "kind": "scan", "name": "grype", "file": "grype.sarif", "format": "sarif", "data": { "tool": "grype" } },
              { "kind": "scan", "name": "semgrep", "file": "semgrep.sarif", "format": "sarif", "data": { "tool": "semgrep" } }
            ]

On this page