This action can comment a list of the vulnerabilities that are currently found and not have not yet been resolved within a repository.
on:
pull_request:
branches: [develop]
types: [opened]
jobs:
vulnerability-report:
runs-on: ubuntu-latest
steps:
- uses: recognizegroup/recognize-vulnerability-report-action@v1
# with:
# github-app-id: ${{ secrets.VULNERABILITY_REPORT_GITHUB_APP_ID }}
# github-app-installation-id: ${{ secrets.VULNERABILITY_REPORT_GITHUB_INSTALLATION_ID }}
# github-app-private-key: ${{ secrets.VULNERABILITY_REPORT_GITHUB_PRIVATE_KEY }}