01tek/npm-security-score

World-class security scoring system for npm packages

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Nov 28, 2025
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: 01tek/npm-security-score@a9a632fbc21b38baf7420fb9624c8ef375ae877b # v0.1.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
packagePackage name to score (or path to package.json for dependency scanning)nopackage.json
fail-belowFail if score is below this thresholdno70
configPath to config fileno
github-tokenGitHub token for PR comments (optional)no
comment-on-prComment on PR with resultsnotrue
json-outputOutput results as JSONnofalse
verboseVerbose outputnofalse
namedescription
scoreSecurity score (0-100)
bandScore band (SAFE, REVIEW, HIGH_RISK, BLOCK)
passedWhether the check passed
reportFull JSON report