lexes7/XSEC security scan

Scan a repository for vulnerabilities in AI-written code and (optionally) upload SARIF to GitHub code scanning.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathFile or directory to scan.no.
fail-onFail the job if any finding is at or above this severity (INFO/LOW/MEDIUM/HIGH/CRITICAL). Empty disables gating.noHIGH
min-severityHide findings below this severity.noLOW
depsAlso scan dependencies for known CVEs (true/false).nofalse
sarif-fileWrite SARIF output to this path (for upload to code scanning). Empty disables.noxsec.sarif
extraspip extras to install, e.g. 'treesitter,deps'.notreesitter,deps

no outputs