rdy checks whether a release artifact matches its Git source and whether its shipped dependencies have unresolved vulnerabilities. It embeds Syft and Grype, checks numeric release versions and missing patches, applies optional triage and identity aliases, and produces Markdown, JSON and VEX evidence. Untriaged Critical/High findings, KEV findings under the default blocking policy, and source problems fail the release. Warnings are informational by default.
fictional-app 1.2.3 PASS | source ok | 0 Critical, 0 High untriaged | 0 Medium | 0 KEV untriaged
Download the matching binary, SHA256SUMS, and SHA256SUMS.sigstore.json from Releases. Install cosign v3.1.3 to verify signatures. Replace the example tag with the downloaded release:
tag=v0.1.0
cosign verify-blob --bundle SHA256SUMS.sigstore.json \
--certificate-identity "https://github.com/jmurray2011/rdy/.github/workflows/release.yml@refs/tags/$tag" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
chmod +x rdy-linux-amd64
./rdy-linux-amd64 --version
# Or build from source (Go 1.26.8):
go install github.com/jmurray2011/rdy/cmd/rdy@latestThe selected binary must appear as OK in the checksum output. Each binary also has a .sigstore.json verification bundle and .cdx.json SBOM. Verify GitHub provenance with gh attestation verify rdy-linux-amd64 --repo jmurray2011/rdy. Releases include LICENSE, NOTICE and THIRD_PARTY_NOTICES. SHA tools differ on macOS/Windows; use an equivalent SHA-256 check there.
Use a local Git clone with release tags fetched, and an artifact whose version matches the release:
printf '[]\n' > triage.yaml
rdy --name fictional-app --release 1.2.3 --artifact build/app.jar \
--repo . --branch main --commit FULL_COMMIT_SHA --triage triage.yaml --out reportRead report/report.md after either PASS or FAIL. findings.json contains provenance, effective options and machine-readable findings; triage.vex.json contains matched decisions. The first run downloads Anchore's advisory database; choose a persistent cache with --db-cache.
| Exit | Meaning |
|---|---|
| 0 | PASS; help or version output also exits 0 |
| 1 | FAIL, including when notification fails |
| 2 | Usage, input, extraction, scanner or report error |
| 3 | PASS, but webhook notification failed |
| Flags | Purpose |
|---|---|
--name, --release |
Required display name and numeric candidate version |
--artifact |
JAR, WAR, RPM or DEB; alternative to --sbom |
--sbom, --artifact-version |
CycloneDX JSON plus required declared version; evidence is declared, not extracted |
--repo, --branch, --commit |
Required local clone and branch; optional full source commit assertion |
--triage, --out |
Required triage YAML and report directory |
--line, --tag-pattern |
Optional release prefix and regex with exactly one numeric-version capture group |
--aliases |
Explicit runtime/advisory and rename identity mappings |
--min-components |
Minimum candidate SBOM component count; default 1 |
--baseline, --deployed, --baseline-dev-sbom |
Optional deployed artifact/SBOM, display label and declared npm fallback |
--dev-sbom |
Deprecated declared npm fallback; not verified shipped |
--kev-policy |
block (default) or report |
--strict, --allow-warning |
Fail on warnings; allow selected stable IDs (repeatable or comma-separated) |
--db-cache, --offline |
Persistent advisory cache; scan using a valid fresh cache without updates |
--notify-webhook |
Post verdict; defaults to RDY_WEBHOOK |
--version, --help |
Version/commit/Go metadata or usage |
This separate mode supports webpack module graphs and npm package-lock v2/v3. It writes the shipped npm SBOM before minification; no source maps are needed.
| Flags | Purpose |
|---|---|
--bundle-stats |
Required webpack stats JSON; deleted after successful generation |
--lockfile |
Required npm package-lock.json v2/v3 |
--bundle-out |
Required output named bundle.cdx.json, packaged inside the artifact |
rdy --bundle-stats build/bundle-stats.json --lockfile package-lock.json --bundle-out build/bundle.cdx.jsonWarnings have stable IDs in JSON (id, message) and reports ([id] message); see the complete ID table. By default they never affect PASS/FAIL or exit codes. --allow-warning without strict mode has no effect and is noted once in the report. Unknown IDs are usage errors listing the valid IDs.
For unattended CI gates that only inspect the exit code, opt into --strict. Every warning blocks unless its ID is allowed. Allowed warnings remain visible as (allowed); failures include strict: N blocking warnings.
rdy ... --strict --allow-warning tags-ignored,frontend-not-coveredRun rdy in the workflow that builds the artifact, after the build step and before anything publishes it. A non-zero exit stops the job, so a failing release never ships. Example GitHub Actions steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with: {fetch-depth: 0}
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830
with:
path: .cache/rdy/db
key: rdy-db-${{ runner.os }}-${{ github.run_id }}
restore-keys: rdy-db-${{ runner.os }}-
- run: rdy --name fictional-app --release 1.2.3 --artifact build/app.jar --repo . --branch HEAD --commit "$GITHUB_SHA" --triage triage.yaml --db-cache .cache/rdy/db --out reportWhy each piece is there:
fetch-depth: 0: the default checkout is a shallow clone without tags. rdy compares--releaseagainst your existing release tags (a version lower than the latest tag fails) and lists commits from the previous release that are missing from this one. Both need full history and tags; a shallow clone produces ashallow-repowarning and incomplete results.--branch HEAD: a tag-triggered workflow checks out a detached commit, so there is no localmainto name.HEADis the commit that was checked out and built.--commit "$GITHUB_SHA": asserts that the checked-out source is the commit that triggered the workflow. A mismatch fails the gate.actions/cachewith--db-cache: keeps the advisory database between runs instead of downloading it every time. Therun_idkey saves a fresh copy after each run andrestore-keysrestores the newest one. rdy still updates the database on each online run; see database freshness.
JAR, WAR, RPM (including RPM 6 payloads), DEB and CycloneDX SBOM on Linux, macOS and Windows. Extraction is built in; no external tools are needed.
JAR/WAR versions come from Implementation-Version; RPM VERSION ignores release and strips ~/^ suffixes; DEB Version strips epoch and revision. Containers, plain binaries, wheels and npm tarballs use --sbom instead of --artifact. Numeric tags allow leading v; prerelease tags are ignored. Calendar releases work (for example --release 2026.10.2); use --tag-pattern '^api-v([0-9]+(?:\.[0-9]+)*)$' for prefixed numeric tags.
Triage · Aliases · Frontend evidence · KEV · Database/offline · Coverage limits · Architecture. See CONTRIBUTING for builds and tests, and SECURITY for private reporting.
rdy does not bundle or redistribute the vulnerability database. It downloads Anchore's database, assembled from upstream feeds with mixed licenses and terms; consult Grype data sources. Reports include provider-derived advisory text.
Apache-2.0, Copyright 2026 Josh Murray. NOTICE points to THIRD_PARTY_NOTICES, which is generated from the release binaries and attached to each release; it includes upstream notices, elected dual licenses and MPL source URLs. Run sh scripts/third-party-notices.sh to generate it locally.