homeofe/Supply Chain Guard

Scan your repository for supply-chain malware indicators. Detects GlassWorm and similar campaigns.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to scan (defaults to repository root)no.
formatOutput format for the report/PR comment: text, json, markdown, sarif, sbom, html, badge, gitlab, junitnomarkdown
min-severityMinimum severity to report: critical, high, medium, low, infonolow
exclude-rulesComma-separated list of rule IDs to excludeno""
fail-onFail the check if findings at this severity or above are found: critical, high, medium, lownocritical
comment-on-prPost findings as a PR comment (true/false)notrue
namedescription
scoreRisk score (0-100)
risk-levelRisk level: clean, low, medium, high, critical
findings-countTotal number of findings
reportFull scan report in the requested format