Scan a container image for vulnerabilities with Sweet Security Mint and report image-lifecycle / code-owner ("who to blame") context back to Sweet — directly from your GitHub Actions workflow.
When you supply a Sweet API key, Mint automatically detects the GitHub Actions environment and attaches the commit, author, branch, pull request and workflow-run context to the scan, so findings in the Sweet platform are tied to the change and the person that introduced them.
name: Scan image with Sweet Mint
on:
push:
branches: [main]
pull_request:
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Build image
run: docker build -t my-org/app:${{ github.sha }} .
- name: Scan with Sweet Mint
uses: sweet-security/mint-scan-action@v1
with:
image: my-org/app:${{ github.sha }}
api-key: ${{ secrets.SWEET_API_KEY }}
sweet-secret: ${{ secrets.SWEET_SECRET }}
fail-on: highScanning an image that already lives in a registry (no local build needed):
- name: Scan with Sweet Mint
uses: sweet-security/mint-scan-action@v1
with:
image: ghcr.io/my-org/app:1.4.2
from: registry
api-key: ${{ secrets.SWEET_API_KEY }}
sweet-secret: ${{ secrets.SWEET_SECRET }}| Input | Required | Default | Description |
|---|---|---|---|
image |
yes | — | Image reference to scan (e.g. my-org/app:1.2.3). |
api-key |
yes | — | Sweet API key. Store as a secret and pass ${{ secrets.SWEET_API_KEY }}. |
sweet-secret |
yes | — | Sweet Secret paired with the API key to authenticate reporting. Store as a secret and pass ${{ secrets.SWEET_SECRET }}. |
fail-on |
no | '' |
Fail the job when a vulnerability of at least this severity is found: negligible, low, medium, high, critical. Empty = never fail on severity. |
output |
no | table |
Report format: table, json, cyclonedx, template. Comma-separate to produce several. |
output-file |
no | '' |
Write the report to this file instead of stdout. |
only-fixed |
no | false |
Only report vulnerabilities that have a fix available. |
platform |
no | '' |
Platform to scan for multi-arch images (e.g. linux/amd64). |
from |
no | '' |
Source scheme mint uses to load the image (registry, docker, oci-archive, oci-dir, …). Empty behaves as docker. |
verbose |
no | '' |
Verbosity flag passed straight to mint (-v, -vv). Empty = mint's default verbosity. |
extra-args |
no | '' |
Additional raw arguments appended to the mint command line. |
fail-on-report-error |
no | false |
Advanced: fail the job if reporting to Sweet fails. By default, reporting errors are logged and ignored. |
sweet-mint-image |
no | registry.sweet.security/mint:prod |
The mint container image (name:tag) to run the scan with. Override to pin a specific tag or digest. |
| Output | Description |
|---|---|
report-file |
Path to the written report file, when output-file was provided. |
When api-key is set, Mint reads the standard GitHub Actions environment (GITHUB_*) and the local event payload (GITHUB_EVENT_PATH) to build the commit / author / branch / PR / workflow context. It supports the push, pull_request, and workflow_dispatch events. No GITHUB_TOKEN and no extra permissions are required — the action never calls the GitHub API. The scan target must resolve to a container image for the report to be produced.
- Linux runner with Docker (
runs-on: ubuntu-latestor anotherubuntu-*image). Mint runs from its container imageregistry.sweet.security/mint(multi-arch:linux/amd64+linux/arm64), so the runner must be able to pull from that registry. - A Sweet API key stored as an encrypted secret, to report results to Sweet.
- To scan a locally-built image via the default Docker daemon (
fromunset /from: docker), the image must exist on the runner (e.g. built withdocker buildin an earlier step); the action mounts the runner's Docker socket into the mint container so it can see it. To scan a registry image (no socket needed), setfrom: registry.
- The API key and
sweet-secretare handed to the mint container by environment-variable name only (docker run -e SWEET_API_KEY -e SWEET_SECRET), so their values never appear on the command line, in the process list, or in the workflow logs. Always pass them via encrypted secrets. - Mint runs from Sweet's container image (
registry.sweet.security/mint:prodby default, set via thesweet-mint-imageinput), pulled by the runner (Docker layer-caches it on persistent / self-hosted runners). The defaultfrom: dockerpath mounts the runner's Docker socket into the mint container so it can scan locally-built images — a standard scanner pattern, but note that it grants the container access to the host Docker daemon. Pin this action to a release tag (e.g.@v1) or a commit SHA for reproducible workflows.
Releases are tagged vX.Y.Z, with a moving major tag (vX) that always points at the latest release in that major line. Pin to @v1 for automatic patch/minor updates, or to a full @vX.Y.Z / commit SHA to pin exactly.