mario-fribla-gonzalez/Node Dependency Check

Scan project dependencies for vulnerabilities using dependency-check

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 23, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: mario-fribla-gonzalez/reuse-dependency-check@25d9250e1293579b7fd894df3ba43ed9edd2317a # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
projectProject nameno${{ github.event.repository.name }}
pathPath to scanno.
argsExtra arguments for dependency-checkno--disableCentral --failOnCVSS 7 --enableRetired --noupdate --disableNodeAudit --nodeAuditSkipDevDependencies --disableOssIndex
versionDependency-Check version to useno12.1.0
formatReport format(s), comma separated (e.g. HTML, XML, JSON)noXML,JSON,HTML
outOutput directory for reportsnoreports
workdirWorking directory to run the scan fromno.

no outputs