himanshu-sangshetti/Autonomous SOC

Supply chain checks: SBOM diff, provenance, vulnerability and secret scan, AI triage, reports

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
policyPolicy mode: strict, moderate, or auditnomoderate
sbom-formatSBOM format: cyclonedx or spdxnocyclonedx
fail-on-blockFail the build when AI triage says AUTO_BLOCKnotrue
grype-severityMinimum Grype severity to fail on: negligible, low, medium, high, criticalnohigh
skip-aiSkip AI triage, use policy engine only (no API key needed)nofalse
working-directoryDirectory for optional npm audit fix (repository-relative, e.g. demo/app)no.
apply-npm-audit-fixIf true, run npm audit fix --ignore-scripts in working-directory after triage (opt-in)nofalse

no outputs