actions-marketplace-validations/VICE Security Audit

Audit your project for security vulnerabilities. Posts findings on PRs and maintains a security badge in your repo.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathProject path to audit (default: repo root)no.
min-scoreMinimum score required to pass (0-100)no70
fail-on-scoreFail the workflow if score is below min-scorenotrue
comment-prPost a comment on pull requests with the scan resultsnotrue
update-badgeUpdate the security badge file on push eventsnotrue
badge-pathPath to the badge JSON file (relative to repo root)no.github/vice-badge.json
upload-sarifUpload SARIF report to GitHub Code Scanning (Security tab). Requires security-events: write permission.notrue
github-tokenGitHub token used for posting PR comments and committing the badgeno${{ github.token }}
namedescription
scoreSecurity score from 0 to 100
gradeSecurity grade from A to F
total-findingsTotal number of findings
critical-findingsNumber of critical findings
high-findingsNumber of high severity findings
report-pathAbsolute path to the JSON report file produced by the scan