ActionRank

uppt

Actively maintained

danielroe/uppt

A composite GitHub Action that turns conventional commits into a draft release PR, tags the PR on merge, and stages publishing to npm via OIDC trusted publishing.

171 starsLast commit todayLatest v0.6.9
B
84
/ 100
Security 100Maintenance 100Popularity 41Reliability 70

Security signals

OpenSSF ScorecardNo data
SECURITY.md presentYes
Immutable releasesEnabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: danielroe/uppt@09882a5a0a1a20a0e802613a77ad59fcb1c1611c # v0.6.9

Mutable tags like v0.6.9 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: danielroe/uppt@09882a5a0a1a20a0e802613a77ad59fcb1c1611c # v0.6.9

Score breakdown

Security (35%)100
Popularity (20%)41
Maintenance (30%)100
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for uppt
Markdown
[![ActionRank](https://actionrank.dev/api/badge/danielroe-uppt)](https://actionrank.dev/actions/danielroe-uppt)
HTML version
HTML
<a href="https://actionrank.dev/actions/danielroe-uppt"><img src="https://actionrank.dev/api/badge/danielroe-uppt" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for uppt

We'll email you only if uppt becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address