ossillate-inc/Packj Security Audit

Use Packj to avoid malicious and other "risky" open-source software dependencies

View on GitHub

Trust Signals

Scorecard Score
Scorecard 2–4scored Jul 6, 2026
Maintenance Recency
Stalelast commit Aug 29, 2023
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: ossillate-inc/packj-github-action@361bddfeb80c5b0908a5ea75c703a5da6c038f03 # v0.0.12-beta

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
DEPENDENCY_FILESA string params passed to Packj for auditingyes
REPO_TOKENYour repo GITHUB_TOKENyes

no outputs