nauta-ai/Holster Scan

Scan for hallucinated or typosquatted package imports and emit SARIF.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jun 10, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: nauta-ai/holster-scan@fb5bde1dfc6dd806ff4bcc297dc1a1e3187cca91 # v0

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathRepository path to scan.no.
fail-onFail threshold: high or medium.nohigh
configOptional path to .holster.yml.no""
offlineDisable registry lookups.nofalse
upload-sarifUpload SARIF to GitHub code scanning.notrue

no outputs