icl-ml4csec/Commit Verification

Verifies commit signatures for both repository commits and third-party dependencies

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
repositoryThe full GitHub repository (e.g. owner/repo)yes
branchThe branch nameyes
tokenGitHub tokenyes
commits-to-checkNumber of commits to check (or 'all')noall
time-rangeTime-range duration for time-based checking (e.g. '6 months', '4320h'). Leave empty for no limitno6 months
key-age-periodCheck PGP key age (e.g. '730h', '1 week'). Leave empty for no requirementno""
repo-policyRepository policy (colon-separated:expired:email-mismatch:uncertified:missingkey:github-automated:unsigned:unregistered)nofalse:false:false:false:true:false:false
deps-policyDependencies policy (colon-separated:expired:email-mismatch:uncertified:missingkey:github-automated:unsigned:unregistered)notrue:true:true:true:true:true:true
output-formatOutput format ('json' or 'console')noconsole
output-fileOutput file name for JSON reportsnosignature-report.json

no outputs