salsadigitalauorg/NPM Compromised Package Scanner
Scan your repository for compromised npm package versions using a curated list (bundled by default)
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| list-url | Optional override URL/ref for compromised_packages.json | no | — |
| warn-only | Deprecated in favor of env NPM_VALIDATOR_WARN_ONLY | no | — |
| psa-id | Optional PSA identifier to include in report summary | no | — |
Outputs
| name | description |
|---|---|
| findings | Number of findings detected |
| report-path | Path to JSON report artifact |
| summary-path | Path to generated Markdown summary |
| inventory-path | Path to generated package inventory text file |