maksemen2/trustmod

Review Go dependency risk in pull requests

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
commandCommand to run: audit, diff, or checknodiff
argsExtra trustmod arguments, parsed with shell-style quotingno""
baseBase ref for diffnomain
formatReport format for stdoutnohuman
policyPolicy file pathno""
baselineBaseline file pathno""
rulesCustom source rules YAML pathno""
sarifOptional SARIF output pathno""
offlineRun in offline modenofalse
govulncheckRun govulncheck when availablenofalse
install-govulncheckInstall a pinned govulncheck before runningnofalse
govulncheck-versiongovulncheck module version to installnolatest
concurrencyMaximum concurrency per analysis phaseno""
timeoutPer-command/provider timeout, such as 30sno""
strict-dataFail when an enabled data provider failsnofalse
namedescription
exit-codeExit code returned by the primary trustmod command
sarif-pathSARIF file path written by the optional SARIF step