actions-marketplace-validations/owasp-dep-scan
dep-scan is a fully open-source security audit tool for project dependencies based on known vulnerabilities and advisories.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| src | Source directory to scan. Defaults to workspace | no | /github/workspace |
| report_file | Output file for the generated report. Defaults to reports/depscan.json | no | /github/workspace/reports/depscan.json |
| profile | Name of the profile to use (appsec, research, operational, threat-modeling, license-compliance, generic) | no | generic |
| thank_you | Indicate you have sponsored OWASP dep-scan | no | I have not sponsored OWASP-dep-scan. |
Outputs
no outputs