GitHub Action for primer — scans manifests and lockfiles for vulnerabilities before they reach your project.
permissions:
security-events: write # SARIF upload
pull-requests: write # PR comments
actions: read
contents: read
steps:
- uses: actions/checkout@v6
- uses: barestripehq/primer-action@v1
with:
file: package-lock.json| Input | Required | Default | Description |
|---|---|---|---|
file |
yes | — | Manifest or lockfile to scan (pyproject.toml, package-lock.json, Cargo.lock, etc.) |
threshold |
no | high |
Minimum severity that blocks the check: critical, high, medium, low |
upload-sarif |
no | true |
Upload SARIF results to GitHub Security tab |
comment-pr |
no | true |
Post a findings summary as a PR comment |
fail-on-findings |
no | true |
Exit 1 when blocking findings are detected |
primer-version |
no | latest |
Pin a specific primer release tag (e.g. v0.1.5) |
token |
no | github.token |
GitHub token for SARIF upload and PR comments |
| Output | Description |
|---|---|
findings-count |
Total vulnerabilities found |
blocking-count |
Findings at or above the threshold |
sarif-path |
Absolute path to the generated SARIF file |
- uses: barestripehq/primer-action@v1
with:
file: backend/pyproject.toml
- uses: barestripehq/primer-action@v1
with:
file: frontend/package-lock.json- uses: barestripehq/primer-action@v1
with:
file: Cargo.lock
fail-on-findings: 'false'- uses: barestripehq/primer-action@v1
with:
file: pyproject.toml
threshold: mediumLinux (x86_64, ARM64), macOS (Intel, Apple Silicon), and Windows (x86_64).
MIT