esbenwiberg/stakeout
Fail PRs whose lockfile diff introduces npm package versions younger than the configured minimum age, unless covered by a CVE exemption in .stakeout.yml.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| config | Path to the stakeout config file | no | .stakeout.yml |
| base-ref | Base ref to diff the lockfile against (defaults to the PR base branch) | no | "" |
| report | Where to write the machine-readable JSON report | no | stakeout-report.json |
Outputs
no outputs