ActionRank

Bridgecrew Github Action

Abandoned

bridgecrewio/bridgecrew-action · MIT

This GitHub Action runs Bridgecrew against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.

73 starsLast commit 1 year agoLatest v1.2343.0
F
39
/ 100
Security 50Maintenance 10Popularity 41Reliability 70

Security signals

OpenSSF ScorecardNo data
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: bridgecrewio/bridgecrew-action@3abfc46acb95827cc9a884e1e4400c5b3228eac1 # v1.2343.0

Mutable tags like v1.2343.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: bridgecrewio/bridgecrew-action@3abfc46acb95827cc9a884e1e4400c5b3228eac1 # v1.2343.0

Score breakdown

Security (35%)50
Popularity (20%)41
Maintenance (30%)10
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for Bridgecrew Github Action
Markdown
[![ActionRank](https://actionrank.dev/api/badge/bridgecrewio-bridgecrew-action)](https://actionrank.dev/actions/bridgecrewio-bridgecrew-action)
HTML version
HTML
<a href="https://actionrank.dev/actions/bridgecrewio-bridgecrew-action"><img src="https://actionrank.dev/api/badge/bridgecrewio-bridgecrew-action" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for Bridgecrew Github Action

We'll email you only if Bridgecrew Github Action becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address