pedrolacerda/Scan a PR for vulnerable dependencies
Scan a PR to check if any of its commits add vulnerable dependencies to the repo
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
- Runtime
- Deprecated runtime
Inputs
| name | description | required | default |
|---|---|---|---|
| GITHUB_TOKEN | GitHub Token for API authentication | yes | — |
Outputs
| name | description |
|---|---|
| severity | Severity of the vulnerability |
| patchedVersion | First patched version |
| vulnerableVersion | Vulnerable version range |