nauta-ai/Holster Scan
Scan for hallucinated or typosquatted package imports and emit SARIF.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Activelast commit Jun 10, 2026
- License
- None
Pinned Snippet
uses: nauta-ai/holster-scan@fb5bde1dfc6dd806ff4bcc297dc1a1e3187cca91 # v0tags can be moved; commit SHAs can't. why a SHA?
Inputs
| name | description | required | default |
|---|---|---|---|
| path | Repository path to scan. | no | . |
| fail-on | Fail threshold: high or medium. | no | high |
| config | Optional path to .holster.yml. | no | "" |
| offline | Disable registry lookups. | no | false |
| upload-sarif | Upload SARIF to GitHub code scanning. | no | true |
Outputs
no outputs