andrewmw94/Tandem Security Analysis

Submit a repository to Tandem and report command-injection findings in CI.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
api-keyCustomer API key for Tandem.yes
api-urlBase URL for the Tandem analyses API.nohttps://api.cogitemus.com/v1/analyses
entrypointOptional repository-relative entrypoint. Tandem discovers package.json when omitted.no""
fail-on-findingsFail the workflow when command-injection paths are found.nofalse
poll-interval-secondsSeconds to wait between status checks.no5
timeout-secondsMaximum time to wait for an analysis.no1800
upload-artifactUpload tandem-result.json as a workflow artifact.notrue
artifact-nameName of the uploaded result artifact.notandem-analysis
namedescription
statusFinal Tandem job status.
findingsNumber of command-injection paths found.
job-idTandem analysis job ID.
result-fileAbsolute path to the JSON result file.