Scanning from CI
A single Node.js file with no dependencies. It uploads an SBOM, waits for the analysis, saves the report and sets the exit code based on the tier you choose.
Set it up
- Download ci-scan.mjs, read it, and commit it to the repository being checked, for example as scripts/ci-scan.mjs.
- Use Node.js 22 or later.
- Generate your SBOM earlier in the build. The script doesn’t create one.
SBOMTRIAGE_URL=https://sbomtriage.dev node scripts/ci-scan.mjs sbom.json
The only argument is the file to scan. It goes to the same endpoint as an upload on the site, so it accepts the same formats. The script allows up to 20 MB, and the deployment may set a lower limit.
Settings
- SBOMTRIAGE_URL
- The deployment to use. Default https://sbomtriage.dev. It must use HTTPS (plain HTTP is allowed only for localhost) and can’t contain a user name or password.
- SBOMTRIAGE_FAIL_ON
- fix-now (default) fails on any Fix now finding, fix-soon on Fix now or Fix soon, and none never fails on tier. Suppressed findings don’t count.
- SBOMTRIAGE_OUTPUT
- Where the files are written. Default sbomtriage-results.
Exit codes and output
- 0
- The gate you configured passed. That doesn’t mean there are no vulnerabilities.
- 1
- At least one unsuppressed finding is in a tier you chose to fail on.
- 2
- The assessment was incomplete (for example, a data source didn’t answer), or something went wrong, such as a bad response, a timeout or an HTTP error. This applies even with none.
It writes report.json and report.html to the output directory. The script waits up to about two minutes for the analysis, gives each request 30 seconds, and refuses redirects.
GitHub Actions
This workflow runs when you trigger it by hand and needs no write permissions. If your organisation requires it, pin the actions to reviewed commit SHAs.
name: Dependency security evidence
on: workflow_dispatch
permissions:
contents: read
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'
- name: Scan inventory
env:
SBOMTRIAGE_URL: https://sbomtriage.dev
SBOMTRIAGE_FAIL_ON: fix-now
run: node scripts/ci-scan.mjs sbom.json
- name: Retain evidence
if: always()
uses: actions/upload-artifact@v4
with:
name: dependency-security-evidence
path: sbomtriage-results/
retention-days: 7
if-no-files-found: warnBefore you rely on it
- It uses the anonymous scan. The report isn’t added to a project, and it’s deleted after 24 hours.
- Anyone with a report’s address can open it until then. Keep build logs and artifacts that contain it private.
- Don’t run it automatically on pull requests from people you don’t trust. Only scan private inventories on a deployment your organisation has approved.
- Scan capacity limits apply. A busy service can return an error, and the script then exits with 2.