Skip to content

Find license compliance and security issues in your applications with FOSSA and Github Actions

License

Notifications You must be signed in to change notification settings

kayinoluwa/fossa-action

 
 

Repository files navigation

FOSSA Action

FOSSA Status FOSSA Action

Find license compliance and security issues in your applications with FOSSA in Github Actions, using latest FOSSA CLI.

About FOSSA

  • Developer focused open source license and security compliance
  • The most in-depth and insightful visibility into your third-party dependencies.
  • Secure your open source code with accurate vulnerability detection and continuous integration

About FOSSA Action

FOSSA Action provides an easy to use entry point to using FOSSA in your github workflow. This github action will run FOSSA CLI in your github workflows with, at minimum, an API key. Below you can find input documentation and examples.

FOSSA Action will run on any linux runner or on a MacOS runner. Note: In order to use container scanning, a running docker daemon is required - unfortunately Github's MacOS runner does not provide docker.

Windows is not currently supported.

Versioning

Please note: Versioning of this action does not correspond to the version of FOSSA CLI. This Action will always use the latest version of FOSSA CLI found here.

Inputs

api-key

Required Your FOSSA API key Example

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}

run-tests

Optional If set to true FOSSA will run the fossa test command.

If not set or set to false FOSSA will run normal scan behavior. In order to run tests, a scan must first be completed. Example

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          run-tests: true

container

Optional A container name or OCI image path. Set to use FOSSA's container scanning functionality. This will run fossa container analyze (default behavior) and fossa container test (if used in combination with run-tests).

If not set FOSSA will run normal scan behavior. Example

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          container: ubuntu:20.04

branch

Optional Branch passed to FOSSA CLI.

Example

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          branch: some-feature-branch

endpoint

Optional Endpoint passed to FOSSA CLI. Defaults to app.fossa.com. Read more.

Example

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          endpoint: fossa.my-company.com

Examples

We've provided a few examples of how to use FOSSA's Github Action in your own project. These examples use an API key stored as a Github secret environment variable fossaAPiKey.

Running a scan

This runs a basic FOSSA scan using FOSSA CLI on a your checked out project.

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}

Running tests

This run fossa tests after doing an initial scan.

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - name: "Checkout Code"
        uses: actions/checkout@v3

      - name: "Run FOSSA Scan"
        uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}

      - name: "Run FOSSA Test"
        uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          run-tests: true

Running Container Scanning

Running container scanning is extremely similar to running FOSSA with a traditional project. This example runs a scan then runs tests. ubuntu:20.14 can be replaced with your newly build docker or OCI image.

jobs:
  fossa-scan:
    runs-on: ubuntu-latest
    steps:
      - name: "Checkout Code"
        uses: actions/checkout@v3

      - name: "Run FOSSA Scan"
        uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          container: ubuntu:20.04

      - name: "Run FOSSA Test"
        uses: fossas/fossa-action@main # Use a specific version if locking is preferred
        with:
          api-key: ${{secrets.fossaApiKey}}
          container: ubuntu:20.04
          run-tests: true

About

Find license compliance and security issues in your applications with FOSSA and Github Actions

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages

  • TypeScript 55.2%
  • JavaScript 44.8%