ClamAV Malware Scanner
ClamAV Malware Scanner - Reusable Workflow
Runs the ClamAV scanner via the argus Python CLI. Equivalent to: python -m argus scan clamav
For GHES users: Use the composite action directly instead of this workflow. See: examples/github-enterprise/all-scanners.yml
uses: huntridge-labs/argus/.github/workflows/scanner-clamav.yml@1.12.2
Triggers
- Manual dispatch
- Reusable (called by other workflows)
Permissions
| Scope | Access |
|---|---|
contents |
read |
security-events |
write |
actions |
read |
pull-requests |
write |
Inputs
| Input | Description | Required | Default |
|---|---|---|---|
allow_failure |
When true (default) the scan never fails the job (non-blocking); when false, a scan crash or a fail_on_severity breac... boolean | No | True |
post_pr_comment |
Whether to post PR comments boolean | No | True |
enable_code_security |
Whether GitHub Code Security is enabled for this repository boolean | No | False |
scan_path |
Path to scan (file, directory, or archive). Defaults to repository root. string | No | . |
fail_on_severity |
Fail the job if malware is found. ClamAV does not support severity-based filtering - any value other than "none" will... string | No | none |
Jobs
clamav-scan โ ClamAV Malware Scan
Runs on: ubuntu-latest ยท Timeout: 30 minutes ยท Continue on error: Yes
Steps:
- Checkout repository โ
actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 - Set up Python โ
actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 - Install Argus โ
huntridge-labs/argus/.github/actions/setup-argus@1.12.2 - Run scan
- Upload artifacts โ
actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a - Build scanner summary
- Upload scanner summary โ
actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a - Upload SARIF โ
github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 - Comment PR with results โ
huntridge-labs/argus/.github/actions/comment-pr@1.12.2