0fatihyildiz/Wormward Supply-Chain Scan

Read-only scan for PolinRider / TasksJacker / Glassworm supply-chain worm infections. Fails the build on findings and can upload SARIF.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 21, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: 0fatihyildiz/wormward@b2b2d496383d03d66ea0c49ca06783752fa80e02 # v0.1.0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathDirectory to scan (relative to the checked-out repo).no.
historyAlso pickaxe git history (git log --all -S) for payloads scrubbed from the tip. Requires fetch-depth: 0 on checkout.nofalse
sarifAlso write a SARIF report to wormward.sarif for upload to the Security tab.notrue
include-communityInclude lower-confidence community IOC leads (suppressed by default).nofalse

no outputs