Learn · Scanning from CIBrowse

LearnDocumentationScanning from CI

Scanning from CI

A single Node.js file with no dependencies. It uploads an SBOM, waits for the analysis, saves the report and sets the exit code based on the tier you choose.

Set it up

  1. Download ci-scan.mjs, read it, and commit it to the repository being checked, for example as scripts/ci-scan.mjs.
  2. Use Node.js 22 or later.
  3. Generate your SBOM earlier in the build. The script doesn’t create one.
SBOMTRIAGE_URL=https://sbomtriage.dev node scripts/ci-scan.mjs sbom.json

The only argument is the file to scan. It goes to the same endpoint as an upload on the site, so it accepts the same formats. The script allows up to 20 MB, and the deployment may set a lower limit.

Settings

SBOMTRIAGE_URL
The deployment to use. Default https://sbomtriage.dev. It must use HTTPS (plain HTTP is allowed only for localhost) and can’t contain a user name or password.
SBOMTRIAGE_FAIL_ON
fix-now (default) fails on any Fix now finding, fix-soon on Fix now or Fix soon, and none never fails on tier. Suppressed findings don’t count.
SBOMTRIAGE_OUTPUT
Where the files are written. Default sbomtriage-results.

Exit codes and output

0
The gate you configured passed. That doesn’t mean there are no vulnerabilities.
1
At least one unsuppressed finding is in a tier you chose to fail on.
2
The assessment was incomplete (for example, a data source didn’t answer), or something went wrong, such as a bad response, a timeout or an HTTP error. This applies even with none.

It writes report.json and report.html to the output directory. The script waits up to about two minutes for the analysis, gives each request 30 seconds, and refuses redirects.

GitHub Actions

This workflow runs when you trigger it by hand and needs no write permissions. If your organisation requires it, pin the actions to reviewed commit SHAs.

name: Dependency security evidence
on: workflow_dispatch
permissions:
  contents: read
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: '22'
      - name: Scan inventory
        env:
          SBOMTRIAGE_URL: https://sbomtriage.dev
          SBOMTRIAGE_FAIL_ON: fix-now
        run: node scripts/ci-scan.mjs sbom.json
      - name: Retain evidence
        if: always()
        uses: actions/upload-artifact@v4
        with:
          name: dependency-security-evidence
          path: sbomtriage-results/
          retention-days: 7
          if-no-files-found: warn

Before you rely on it

  • It uses the anonymous scan. The report isn’t added to a project, and it’s deleted after 24 hours.
  • Anyone with a report’s address can open it until then. Keep build logs and artifacts that contain it private.
  • Don’t run it automatically on pull requests from people you don’t trust. Only scan private inventories on a deployment your organisation has approved.
  • Scan capacity limits apply. A busy service can return an error, and the script then exits with 2.