gorira-tatsu/aminet Supply Chain Review

Analyze dependency changes in pull requests for security, license, and vulnerability issues

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to the manifest to review. Supports package.json, requirements.txt, and pyproject.toml.package.json
comment-idStable identifier used to match and update the PR comment for this manifest (defaults to the manifest path)no
comment-prefixDisplay label shown in the PR comment title (defaults to the manifest path)no
depthMaximum dependency depthno
deny-licenseComma-separated list of SPDX IDs to denyno
fail-on-vulnExit non-zero on vulnerabilities at or above severityno
securityEnable security deep analysistrue
lockfile-pathExplicit lockfile path used to pin review resolution (monorepos, or poetry.lock / pdm.lock / uv.lock alongside pyproject.toml)no
devInclude devDependencies in review (default: true)true
exclude-packagesComma-separated packages to skip intentionally (supports wildcards, e.g., @scope/*)no
npm-tokennpm auth token for private registries when private packages should be analyzedno
versionPublished aminet version to execute. If omitted, release-tag usage resolves from GITHUB_ACTION_REF; repo-local usage falls back to dist/index.js when available.no

no outputs