emabrey/vcpkg-vuln-scan

Scan a vcpkg-based project for known CVEs via OSV.dev

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
project-rootDirectory containing vcpkg.jsonno.
transitiveWalk transitive port dependenciesnofalse
suppressionsPath to a suppressions JSON file (see repo README)no""
sarifIf set, write SARIF 2.1.0 to this pathno""
jsonIf set, write grouped JSON results to this pathno""
fail-on-findingsFail the step when there are active findingsnotrue
python-versionPython version to install via actions/setup-pythonno3.11
cache-ttl-hoursOSV response cache TTL in hoursno24
namedescription
sarif-pathPath to the generated SARIF file (empty if none was requested)
active-countNumber of active (un-suppressed, non-withdrawn) findings