Autonomous, closed-loop CVE detection and remediation for containerized workloads — local CPU inference, cloud LLMs, or bring your own API key.
|
Watch the complete explainer covering:
|
Read about:
|
Supply Chain Guardian AI is an all-in-one GitHub Action that automatically secures your containerized applications:
- 🔍 Scans your container images using Trivy for
CRITICALandHIGHvulnerabilities. - 🤖 Patches vulnerable Dockerfiles using AI (Local Ollama, NVIDIA NIM, OpenAI, or DeepSeek).
- 🧪 Smoke Tests the patched Dockerfile (
docker build+ runtime health check). - ☸️ Validates deployment stability inside a temporary KinD (Kubernetes in Docker) cluster (optional).
- 🔀 Opens a Pull Request with complete proof and security audit logs.
Push / Cron → Trivy Scan → CVE Found → AI Patches Dockerfile
→ Smoke Test → KinD Validates → Re-scan Confirms → PR Opened
- ⚡ Quickstart
- 📖 Common Workflow Examples
- 🤖 Supported AI Providers
- 📋 Complete Inputs & Outputs
- 🛡️ Security & Reliability Features
- ❓ FAQ & Troubleshooting
- 📄 License
Add this step to your GitHub Actions workflow file (e.g. .github/workflows/security.yml):
name: Security Audit
on:
push:
branches: [main]
pull_request:
branches: [main]
permissions:
contents: write
pull-requests: write
jobs:
scan-and-remediate:
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Run Supply Chain Guardian
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './Dockerfile'No API key required! Uses Ollama (llama3.2:1b) directly on the GitHub Actions runner CPU.
- name: Run Supply Chain Guardian (Local AI)
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './Dockerfile'Fast, high-accuracy inference using cloud AI models.
Prerequisite: Add
NVIDIA_NIM_API_KEY(or your provider's API key) to your Repository Settings → Secrets and variables → Actions.
- name: Run Supply Chain Guardian (NVIDIA NIM)
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './Dockerfile'
provider: 'openai'
model: 'moonshotai/kimi-k2.6' # or 'deepseek-ai/deepseek-v4-flash'
openai-endpoint: 'https://integrate.api.nvidia.com/v1'
api-key: ${{ secrets.NVIDIA_NIM_API_KEY }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}Specify sub-directory paths easily:
- name: Run Supply Chain Guardian (Backend App)
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './backend/Dockerfile'
provider: 'openai'
model: 'z-ai/glm-5.2'
openai-endpoint: 'https://integrate.api.nvidia.com/v1'
api-key: ${{ secrets.NVIDIA_NIM_API_KEY }}If your repository does not deploy to Kubernetes, turn off KinD cluster testing by setting kind-enabled: "false".
- name: Run Supply Chain Guardian (KinD Disabled)
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './Dockerfile'
kind-enabled: 'false'
healthz-port: '5000'
healthz-path: '/health'
create-pr: 'true'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}Runs complete scanning, AI remediation, KinD deployment test, and opens an automated security PR.
name: Supply Chain Security Pipeline
on:
push:
branches: [main]
schedule:
- cron: '0 2 * * *' # Daily security check at 2:00 AM
permissions:
contents: write
pull-requests: write
jobs:
guardian-security:
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Run Supply Chain Guardian
uses: barbaria888/SupplyChain-Guardian-AI-Github_Action@v2
with:
dockerfile: './backend/Dockerfile'
provider: 'openai'
model: 'deepseek-ai/deepseek-v4-flash'
openai-endpoint: 'https://integrate.api.nvidia.com/v1'
api-key: ${{ secrets.NVIDIA_NIM_API_KEY }}
kind-enabled: 'true'
k8s-manifests: './k8s/'
healthz-port: '8080'
healthz-path: '/healthz'
create-pr: 'true'
pr-branch: 'security/auto-cve-patch'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}You can switch between local CPU inference and cloud API providers using the provider and openai-endpoint inputs:
| Provider | provider |
openai-endpoint |
Recommended Models |
|---|---|---|---|
| Local Ollama (Free) | ollama |
N/A | llama3.2:1b (default) |
| NVIDIA NIM | openai |
https://integrate.api.nvidia.com/v1 |
moonshotai/kimi-k2.6, deepseek-ai/deepseek-v4-flash, z-ai/glm-5.2 |
| OpenAI Direct | openai |
https://api.openai.com/v1 |
gpt-4o-mini, gpt-4o |
| Groq / DeepSeek / Custom | openai |
(Your base URL) | Any OpenAI-compatible model |
| Input | Required | Default | Description |
|---|---|---|---|
dockerfile |
No | ./Dockerfile |
Path to the Dockerfile to scan and remediate |
image-ref |
No | '' |
Pre-built image reference (if scanning existing image) |
severity |
No | CRITICAL,HIGH |
Comma-separated Trivy vulnerability severities |
provider |
No | ollama |
AI engine: ollama or openai |
model |
No | (auto) | Model tag or identifier for the provider |
api-key |
No | '' |
API Key for cloud providers (NVIDIA / OpenAI / Custom) |
openai-endpoint |
No | https://integrate.api.nvidia.com/v1 |
OpenAI-compatible endpoint URL |
trivy-version |
No | 0.63.0 |
Trivy CLI version |
kind-enabled |
No | true |
Set to "false" to skip KinD Kubernetes integration tests |
kind-config |
No | .kind/cluster-config.yaml |
Path to custom KinD cluster config |
k8s-manifests |
No | k8s/ |
Directory containing Kubernetes manifests to test in KinD |
healthz-port |
No | 18080 |
Container host port mapped during health check |
healthz-path |
No | / |
Endpoint path probed during container smoke test |
create-pr |
No | true |
Set to "true" to open a PR on successful patch |
pr-branch |
No | auto-patcher/cve-remediation |
Branch name used for the automated PR |
pr-labels |
No | security,automated-patch |
Comma-separated labels applied to the PR |
enforce-non-root |
No | true |
Enforces non-root execution (USER instruction) in patched Dockerfiles |
policy-preset |
No | strict |
Enforcement mode: strict (fail on unresolved CVE) or lax (warn only) |
| Output | Description |
|---|---|
vulnerabilities-found |
"true" if Trivy detected matching vulnerabilities |
patch-applied |
"true" if AI successfully generated a patch |
smoke-test-passed |
"true" if the patched Dockerfile built and booted cleanly |
kind-validation-passed |
"true" if KinD Kubernetes deployment test succeeded |
- 🔒 Zero Egress Option: Use
provider: 'ollama'for 100% offline, privacy-first patching directly inside the GitHub Actions runner. - 🛡️ 3-Layer Hallucination Defense:
- Syntax Whitelist: Inspects generated Dockerfile instructions (
FROM,RUN,COPY, etc.) to prevent LLM hallucinations. - Smoke Test Gate: Verifies
docker buildand runtime container stability (with dummy DB env injection for app boots). - KinD Cluster Verification: Ensures the container deploys into Kubernetes without
CrashLoopBackOff.
- Syntax Whitelist: Inspects generated Dockerfile instructions (
- 📜 Full Auditability: Every run generates a
patch_audit.logartifact containing full LLM prompts, raw outputs, and scan reports.
Ensure your workflow file includes the required permissions:
permissions:
contents: write
pull-requests: writeAlso ensure you pass the GITHUB_TOKEN environment variable:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}Starting in v2.4.0, all discovered Kubernetes manifests automatically have their container image: replaced with the locally built patched image (guardian-scan:patched) and imagePullPolicy: Never. Make sure you are using @v2 (or @v2.4.0+). If your repository does not use Kubernetes, simply set kind-enabled: "false".
MIT License — Created by @barbaria888.
