Nitishkumar-ai/commitguard-env
0
1name: "CommitGuard Scan"2description: "AI-paced vulnerability scanning for code commits."3inputs:4 model:5 description: "The Hugging Face model ID or path to use for scanning"6 required: false7 default: "inmodel-labs/commitguard-llama-3b"8 fail-on-vulnerable:9 description: "Fail the workflow if a vulnerability is found (true/false)"10 required: false11 default: "true"12 github_token:13 description: "GitHub token for PR scanning"14 required: false15 default: ${{ github.token }}16runs:17 using: "docker"18 image: "Dockerfile"19 args:20 - "bash"21 - "-c"22 - |23 pip install -e .[scan]24 FAIL_ARG=""25 if [ "${{ inputs.fail-on-vulnerable }}" = "true" ]; then26 FAIL_ARG="--fail-on-vulnerable"27 fi28 # In a PR context, scan the PR diff. Otherwise, scan HEAD.29 if [ "${{ github.event_name }}" = "pull_request" ]; then30 # Needs gh cli or fetching diff manually. For simplicity, scan the latest commit.31 commitguard scan --commit HEAD --format text $FAIL_ARG --model ${{ inputs.model }}32 else33 commitguard scan --commit HEAD --format text $FAIL_ARG --model ${{ inputs.model }}34 fi35 