actions-marketplace-validations/safe-pkgs Audit

Audit project dependencies for supply-chain risks using safe-pkgs

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Apr 5, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: actions-marketplace-validations/math280h_safe-pkgs-action@acc9a104941188967ed9819a220434df64bd47b1 # no releases — HEAD as of 2026-07-10

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to lockfile or project directoryno.
registryRegistry override (npm, cargo, pypi). Auto-detects from lockfile if omitted.no
versionsafe-pkgs release version to downloadnolatest
fail-on-severityFail the workflow if any package meets this severity (low, medium, high, critical, off)nohigh
namedescription
allow"true" or "false" — overall audit result
riskHighest severity found
totalTotal packages audited
deniedNumber of denied packages
jsonRaw JSON output from safe-pkgs