esbenwiberg/stakeout

Fail PRs whose lockfile diff introduces npm package versions younger than the configured minimum age, unless covered by a CVE exemption in .stakeout.yml.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
configPath to the stakeout config fileno.stakeout.yml
base-refBase ref to diff the lockfile against (defaults to the PR base branch)no""
reportWhere to write the machine-readable JSON reportnostakeout-report.json

no outputs