depkeep/ossrisk

Scan dependencies for EOL versions, CVEs, and abandonment signals

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to the project directoryno.
fail-onExit 1 if any dependency reaches this risk level or above (none|low|medium|high|critical)nohigh
no-eolSkip EOL checksnofalse
no-cveSkip CVE checksnofalse
no-activitySkip abandonment/staleness checksnofalse
no-outdatedSkip latest-version checksnofalse
no-typosquatSkip typosquatting checksnofalse
no-licenseSkip license compliance checksnofalse
no-maintainerSkip maintainer/publisher checksnofalse
no-install-scriptSkip install-script (preinstall/postinstall) checksnofalse
direct-onlyScan only direct dependencies, skip transitivesnofalse
github-tokenGitHub token for posting a PR comment with the reportno""
namedescription
risk-levelHighest risk level found across all dependencies