Skip to main content

Running a scan

Every release publishes multi-arch images for linux/amd64 and linux/arm64 to GitHub Container Registry. Mount the code you want to scan and pass CLI arguments after the image name:
Use :latest, or pin a version in CI with a specific tag such as :0.9.0.

Writing output into the mounted folder

The image runs as a non-root user, so writing output directly into the mounted folder (--output /src/results.json) can fail with a permission error. Either redirect stdout on the host, as above, or run the container as your own user so that you own the files it writes:

CI example