Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sweet Security Mint — GitHub Action

Scan a container image for vulnerabilities with Sweet Security Mint and report image-lifecycle / code-owner ("who to blame") context back to Sweet — directly from your GitHub Actions workflow.

When you supply a Sweet API key, Mint automatically detects the GitHub Actions environment and attaches the commit, author, branch, pull request and workflow-run context to the scan, so findings in the Sweet platform are tied to the change and the person that introduced them.

Quick start

name: Scan image with Sweet Mint
on:
  push:
    branches: [main]
  pull_request:

jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Build image
        run: docker build -t my-org/app:${{ github.sha }} .

      - name: Scan with Sweet Mint
        uses: sweet-security/mint-scan-action@v1
        with:
          image: my-org/app:${{ github.sha }}
          api-key: ${{ secrets.SWEET_API_KEY }}
          sweet-secret: ${{ secrets.SWEET_SECRET }}
          fail-on: high

Scanning an image that already lives in a registry (no local build needed):

- name: Scan with Sweet Mint
  uses: sweet-security/mint-scan-action@v1
  with:
    image: ghcr.io/my-org/app:1.4.2
    from: registry
    api-key: ${{ secrets.SWEET_API_KEY }}
    sweet-secret: ${{ secrets.SWEET_SECRET }}

Inputs

Input Required Default Description
image yes — Image reference to scan (e.g. my-org/app:1.2.3).
api-key yes — Sweet API key. Store as a secret and pass ${{ secrets.SWEET_API_KEY }}.
sweet-secret yes — Sweet Secret paired with the API key to authenticate reporting. Store as a secret and pass ${{ secrets.SWEET_SECRET }}.
fail-on no '' Fail the job when a vulnerability of at least this severity is found: negligible, low, medium, high, critical. Empty = never fail on severity.
output no table Report format: table, json, cyclonedx, template. Comma-separate to produce several.
output-file no '' Write the report to this file instead of stdout.
only-fixed no false Only report vulnerabilities that have a fix available.
platform no '' Platform to scan for multi-arch images (e.g. linux/amd64).
from no '' Source scheme mint uses to load the image (registry, docker, oci-archive, oci-dir, …). Empty behaves as docker.
verbose no '' Verbosity flag passed straight to mint (-v, -vv). Empty = mint's default verbosity.
extra-args no '' Additional raw arguments appended to the mint command line.
fail-on-report-error no false Advanced: fail the job if reporting to Sweet fails. By default, reporting errors are logged and ignored.
sweet-mint-image no registry.sweet.security/mint:prod The mint container image (name:tag) to run the scan with. Override to pin a specific tag or digest.

Outputs

Output Description
report-file Path to the written report file, when output-file was provided.

How reporting / "who to blame" works

When api-key is set, Mint reads the standard GitHub Actions environment (GITHUB_*) and the local event payload (GITHUB_EVENT_PATH) to build the commit / author / branch / PR / workflow context. It supports the push, pull_request, and workflow_dispatch events. No GITHUB_TOKEN and no extra permissions are required — the action never calls the GitHub API. The scan target must resolve to a container image for the report to be produced.

Requirements

  • Linux runner with Docker (runs-on: ubuntu-latest or another ubuntu-* image). Mint runs from its container image registry.sweet.security/mint (multi-arch: linux/amd64 + linux/arm64), so the runner must be able to pull from that registry.
  • A Sweet API key stored as an encrypted secret, to report results to Sweet.
  • To scan a locally-built image via the default Docker daemon (from unset / from: docker), the image must exist on the runner (e.g. built with docker build in an earlier step); the action mounts the runner's Docker socket into the mint container so it can see it. To scan a registry image (no socket needed), set from: registry.

Security notes

  • The API key and sweet-secret are handed to the mint container by environment-variable name only (docker run -e SWEET_API_KEY -e SWEET_SECRET), so their values never appear on the command line, in the process list, or in the workflow logs. Always pass them via encrypted secrets.
  • Mint runs from Sweet's container image (registry.sweet.security/mint:prod by default, set via the sweet-mint-image input), pulled by the runner (Docker layer-caches it on persistent / self-hosted runners). The default from: docker path mounts the runner's Docker socket into the mint container so it can scan locally-built images — a standard scanner pattern, but note that it grants the container access to the host Docker daemon. Pin this action to a release tag (e.g. @v1) or a commit SHA for reproducible workflows.

Versioning

Releases are tagged vX.Y.Z, with a moving major tag (vX) that always points at the latest release in that major line. Pin to @v1 for automatic patch/minor updates, or to a full @vX.Y.Z / commit SHA to pin exactly.

License

Apache-2.0.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages