arnica-io/Arnica Dependency Security Scan

Scan a repository for dependencies and vulnerabilities

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit May 18, 2026
License
MIT

Pinned Snippet

workflow.ymlSHA-pinned
uses: arnica-io/dependency-scan@6b1377a3d111170de80632696039f658f59940e1 # v1.0.31

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
repository-urlRepository URL associated with the scanyes
branchBranch name associated with the scanyesmain
scan-pathRepository path to associate with the scanno.
api-base-urlArnica API base URL (e.g., https://api.app.arnica.io)nohttps://api.app.arnica.io
scan-timeout-secondsMaximum time to wait for scan completion in secondsno900
api-tokenArnica API token (prefer passing via secrets)no
on-findingsBehavior when findings are detected (Failure). One of fail|alert|passnofail
debugEnable verbose API response debug logsnofalse
namedescription
scan-idArnica scan identifier.
statusFinal scan status (Success, Failure, Error, Skipped, Timeout)