raccioly/websec-validator

Local-first security recon that briefs your AI coding agent — SARIF for Code Scanning, can gate PRs on new findings.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathPath to the repo/subdir to scan.no.
scanAlso execute the available static scanners (Trivy/Gitleaks/Semgrep/…) if present.nofalse
fail-onFail the job if any finding at/above this severity remains (critical|high|medium|low). Empty = never fail (report-only).no""
baselineOptional prior findings-ledger.json — gate only on findings NEW since this baseline.no""
upload-sarifUpload results.sarif to the GitHub Security tab (Code Scanning).notrue
outOutput directory.nowebsec-out

no outputs