0fatihyildiz/Wormward Supply-Chain Scan
Read-only scan for PolinRider / TasksJacker / Glassworm supply-chain worm infections. Fails the build on findings and can upload SARIF.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Activelast commit Jul 21, 2026
- License
- MIT
Pinned Snippet
uses: 0fatihyildiz/wormward@b2b2d496383d03d66ea0c49ca06783752fa80e02 # v0.1.0tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| path | Directory to scan (relative to the checked-out repo). | no | . |
| history | Also pickaxe git history (git log --all -S) for payloads scrubbed from the tip. Requires fetch-depth: 0 on checkout. | no | false |
| sarif | Also write a SARIF report to wormward.sarif for upload to the Security tab. | no | true |
| include-community | Include lower-confidence community IOC leads (suppressed by default). | no | false |
Outputs
no outputs