sky2194/Dependency Analyzer Security Scan

Scan your dependencies for CVE vulnerabilities and post a full report to your PR — never blocks your pipeline

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
manifest-filePath to the dependency manifest. Supported: package.json (npm), requirements.txt (PyPI), pom.xml (Maven). If omitted, the Action auto-detects whichever manifest exists in the workspace. nopackage.json
api-urlDependency Analyzer API base URLnohttps://depanalyzer.com
github-tokenGitHub token used to post PR commentsno${{ github.token }}
namedescription
risk-scoreComposite risk score (0–100)
scan-urlURL to view the full scan report in the DepAnalyzer app
criticalNumber of Critical severity CVEs found
highNumber of High severity CVEs found
kev-countNumber of CISA KEV (actively exploited) CVEs found