valinora/GHSS - GitHub Supply-chain Security Audit

Audit GitHub Actions workflows for supply-chain vulnerabilities

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
severity-thresholdMinimum severity to fail on: critical, high, medium, lowyes
github-tokenGitHub token for API access (mutually exclusive with github-app-* inputs)no${{ github.token }}
github-app-idGitHub App ID (alternative to github-token)no
github-app-installation-idGitHub App installation ID (alternative to github-token)no
github-app-private-keyGitHub App private key PEM content (alternative to github-token)no
providerAdvisory provider: ghsa, osv, allnoall
depthRecursive expansion depth (0 = flat, integer, or "unlimited")no0
depsScan dependencies for known vulnerabilities (true/false)nofalse
versionghss release tag to download (e.g. "ghss-cli-v0.2.0" or "latest")noghss-cli-v0.2.0

no outputs