mishelrossmaree/AI-Driven DevSecOps Framework

Reusable DevSecOps action for C/C++ static analysis

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 29, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: mishelrossmaree/ai-driven-devsecops-framework@4d1334ce2b50ca12d17798bb198a6d60288272bc # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
scan-pathPath to scan in the target repositoryno.
ml1-high-thresholdML1 HIGH risk threshold (0-100)no70
ml1-medium-thresholdML1 MEDIUM risk threshold (0-100)no40
ml1-review-confidence-thresholdML1 confidence threshold (0-1) below which risk_level becomes REVIEW_REQUIREDno0.2
ml3-min-rowsMinimum historical ML3 rows required before anomaly model trainingno30
ml3-persist-stateWhether to commit and push ML3 state back to the consuming repositorynofalse

no outputs