github-labeler
AbandonedDeclarative way to configure GitHub labels
★ 77 starsLast commit 3 years agoLatest v0.2.1
F
36
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: babarot/github-labeler@43a2fc6efefc7012d13a015ad7edad218d3d9e34 # v0.2.1Mutable tags like v0.2.1 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: babarot/github-labeler@43a2fc6efefc7012d13a015ad7edad218d3d9e34 # v0.2.1
Score breakdown
Security (35%)50
Popularity (20%)32
Maintenance (30%)4
Reliability (15%)70