acidghost/Renovate Vulnerability Report

Report vulnerabilities in Renovate pull request image updates

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 20, 2026
License
Public domain

Pinned Snippet

workflow.ymlSHA-pinned
uses: acidghost/renovate-vuln-report@fcd637db3d2454c7288b5be53132980d7f29560e # no releases — HEAD as of 2026-07-22

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
report-surfaceReport surface to publish to: summary or pr-commentnosummary
forgeForge hosting the pull request: github, forgejo, or giteanogithub
forge-api-urlForge API URL, usually ${{ github.api_url }}no${{ github.api_url }}
tokenForge token used when report-surface is pr-commentno${{ github.token }}

no outputs