Set up a scanner
Workflow examples that send results from ASH, Grype, Trivy, Semgrep, Checkov and Syft to Prodgator.
Availability
Prodgator reads common report formats, not each scanner's own JSON:
| Report | Format | Use it for |
|---|---|---|
| Scanner findings (code, dependencies, infrastructure as code, secrets) | SARIF 2.1.0 | Almost every scanner can write it |
| Software bill of materials | CycloneDX JSON or SPDX JSON | Components, and CycloneDX vulnerabilities with VEX analysis |
Run your scanner with SARIF output and send the file with the Prodgator report action or the upload API. Grype JSON and Trivy JSON are refused with a message that names the SARIF flag to use instead.
The examples below use the report action, which needs no API key. Each attached file counts as one upload against your plan's per-run limit (Team 3, Business 10, Enterprise unlimited), so a tool that combines several scanners into one file, like ASH, uses one upload. See Limits for file size limits.
Every job that uses the action needs this permission:
permissions:
contents: read
id-token: writePick your scanner
ASH runs several open source scanners and writes one aggregated SARIF file. Its built-in scanners are Bandit, Semgrep, Opengrep, detect-secrets, Checkov, cfn-nag, cdk-nag, npm audit, Grype and Syft, so one upload covers Python and JavaScript code, CloudFormation, CDK and Terraform, secrets and dependencies.
jobs:
ash:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- name: Install ASH
run: pip install git+https://github.com/awslabs/automated-security-helper.git@v3.7.1
- name: Run ASH
run: ash --mode container --no-fail-on-findings
- uses: prodgator/prodgator-action@v1
if: always()
with:
attestations: |
[{ "kind": "scan", "name": "ash", "file": ".ash/ash_output/reports/ash.sarif", "format": "sarif",
"data": { "tool": "ash", "failOn": "high" } }]- runs every built-in scanner and needs Docker (GitHub's Ubuntu runners have it). is faster but runs only the scanners ASH can run from Python.
- keeps the job going so the report is sent. Set on the attestation to decide when the scan counts as failed in Prodgator.
- ASH writes its reports to . Upload . ASH also writes , a trimmed copy for GitHub code scanning that drops result fields such as fingerprints, so Prodgator groups it less precisely.
Source: the ASH README and reporter docs for version 3.7.1 (install command, , and the and paths).
To send several files from one step, see Several scanners in one step. Outside GitHub Actions, see Upload with the API.