acidghost/Renovate Vulnerability Report
Report vulnerabilities in Renovate pull request image updates
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Activelast commit Jul 20, 2026
- License
- Public domain
Pinned Snippet
uses: acidghost/renovate-vuln-report@fcd637db3d2454c7288b5be53132980d7f29560e # no releases — HEAD as of 2026-07-22tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| report-surface | Report surface to publish to: summary or pr-comment | no | summary |
| forge | Forge hosting the pull request: github, forgejo, or gitea | no | github |
| forge-api-url | Forge API URL, usually ${{ github.api_url }} | no | ${{ github.api_url }} |
| token | Forge token used when report-surface is pr-comment | no | ${{ github.token }} |
Outputs
no outputs