glferreira-devsecops/Cascavel Dependency Audit

Scan project dependencies for known CVEs. Supports npm, pip, Go, Ruby, Rust, PHP, and Java.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathProject root to scan for dependency filesno.
severityMinimum CVE severity to report: low, medium, high, criticalnomedium
fail-on-findingsFail the pipeline if vulnerabilities are foundnotrue
ecosystemsComma-separated ecosystems to scan: npm,pip,go,ruby,rust,composer,maven (or "auto")noauto
ignore-cvesComma-separated CVE IDs to ignore (e.g., CVE-2024-1234,CVE-2024-5678)no""
max-age-daysOnly report CVEs published within N days (0 = all)no0
sarif-outputGenerate SARIF report for GitHub Security tabnotrue
namedescription
total-vulnerabilitiesTotal number of vulnerabilities found
critical-countNumber of critical CVEs
high-countNumber of high CVEs
affected-packagesNumber of affected packages
report-pathPath to JSON report
sarif-pathPath to SARIF report