actions-marketplace-validations/SAST-action

GitHub Action examines C/C++ source code and reports possible security weaknesses (“flaws”) sorted by risk level.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stalelast commit Mar 24, 2021
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: actions-marketplace-validations/ivankuchin_sast@b52ccf485dd0f9e63d519e1f1fbdc3cf0a6f155e # no releases — HEAD as of 2026-07-14

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
GITHUB_TOKENGITHUB_TOKEN (automatically assinged by GitHub)yes
DATAONLYDon’t display the header and footer.notrue
SOURCE_CODESource code folder or file to check.no./

no outputs