pablodomi/vsix-scan

Deep security analyzer for VS Code extensions

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
targetExtension to analyze. Accepts: publisher.extensionName (downloads from VS Marketplace), publisher.extensionName@version, path to a .vsix file, or a folder path. yes
formatOutput format: terminal | json | html | sarifnosarif
fail-onFail the action (exit 1) if any finding meets this severity or above. Values: critical | high | medium | low nohigh
rulesPath to an additional YAML rules fileno
upload-sarifUpload SARIF results to the GitHub Security tab. Only applies when format is "sarif". Requires the repo to have GitHub Advanced Security enabled (public repos or GHAS license). notrue
namedescription
risk-scoreNumeric risk score (0–100)
risk-levelRisk level: safe | low | medium | high | critical