jsalvata/lockfile-assay

Verify the committed lockfile derives honestly from reviewable inputs, post the verdict as the App's check run, and memoise passing derivations (anchored form — spec §8). Safe only from an anchored pull_request_target workflow — see docs/setup-github-app.md.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
baseBase ref (the PR merge-base), e.g. the origin merge-base; see examples/lockfile-assay.yml.yes
headHead ref to check — the PR head SHA; see examples/lockfile-assay.yml.noHEAD
prPR number, for the memo consult; see examples/lockfile-assay.yml.yes
app-idThe dedicated App's id, for the consult identity filter.yes
app-tokenGitHub App installation token with Checks: write, from the dedicated App (actions/create-github-app-token). Passed to the CLI as LOCKFILE_ASSAY_TOKEN. See docs/setup-github-app.md.yes

no outputs