Muninn Security Scanner
Version updated for https://github.com/skaldlab/muninn to version v0.3.4.
- This action is used across all versions by 1 repositories.
Action Type
This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed
Changelog
[0.3.4] - 2026-07-04
Changed
- Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep 1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).
[0.3.3] - 2026-06-17
Changed
- Trivy default severity is now all levels (
UNKNOWNthroughCRITICAL) instead ofCRITICALandHIGHonly. osv-scanner and trivy now overlap on medium/low advisories by default so cross-scanner dedup andDetected bywork without extra config. Consumers can narrow the Trivy scan withscanners.trivy.severity;fail-onstill controls which findings fail the run.
[0.3.2] - 2026-06-16
Fixed
- Suppressions with
tooland/orrule-idare now applied. Previously onlyid(path substring) andfingerprintmatchers worked; tool+rule-id entries parsed frommuninn.ymlbut silently no-op’d.
[0.3.1] - 2026-06-16
Fixed
- Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (
rule_id,meta,rules,blobshas) now populate title, rule, and file in PR comments instead of empty shells (File: :0, `Rule: ``) (#41). - Actionlint PR comments: fall back to
kind(e.g.expression) whenrule.nameis absent; omit empty Rule lines. - Poutine injection findings: render
injection_sourcesas formatted Sources instead of plainmeta.detailstext.
Changed
- PR comment layout: shared field helpers; non-dependency findings follow File → Rule → optional extras → description; single-scanner dependency findings use File instead of a redundant Source line.
[0.3.0] - 2026-06-16
Added
- Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new
detected_byfield (surfaced in the JSON report, the PR comment’s “Detected by” line, and adetectedBySARIF result property). A CVE is preferred over GHSA so the same vulnerability converges on one id across scanners (#27). - Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral
[dependency]heading (instead of a single scanner’s name) withPackage,Advisory(including the shared CVE),Detected by, and aSourceslist showing where each scanner observed it. A newsourcesfield on the finding (per-scannertool+file) backs the JSON report (#27).
Fixed
- PR comment rendering: scanner descriptions are flattened to a single line and their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence can no longer swallow later findings and the footer into a code block.
[0.2.0] - 2026-06-15
Supply-chain hardening for the scanner image and signed, verifiable releases (closes #30).
Added
- Pinned every bundled binary scanner to an exact version with SHA256 checksum verification in the Docker image — gitleaks, zizmor, actionlint, poutine, osv-scanner, trivy (#31)
- Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch
requirements-scanners.txtinstalled withpip --require-hashes(#33) - Renovate configuration to auto-PR scanner version bumps, with a CI job that refreshes the pinned checksums (#32)
- Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle
checksums.txt.sigstore.json) (#34) - SBOM (SPDX) attached to every release and as an image attestation (#34)
- Max-mode SLSA build provenance attestation on the container image (#34)
- “Verifying releases” instructions in the README (#34)
Changed
- Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its
aiohttp<3.14cap (#33)
[0.1.0] - 2026-06-14
Added
- 8 security scanners: gitleaks, zizmor, actionlint, poutine, semgrep, osv-scanner, trivy, checkov
- Unified Finding schema with fingerprinting
- Three output formats: SARIF 2.1.0, JSON, GitHub PR comment
- GitHub Action with outputs
- Config-driven scanner behavior via muninn.yml
- Suppression management with expiry dates
- 90%+ test coverage enforced in CI
- Integration tests with real scanner binaries
- Self-scan: Muninn scans itself on every PR
Built by Skald Lab — skaldlab.dev