osv-scanner
Actively maintainedgoogle/osv-scanner-action · Apache-2.0
★ 91 starsLast commit 9 days agoLatest v2.3.8
C
65
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: google/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8Mutable tags like v2.3.8 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: google/osv-scanner-action@9a498708959aeaef5ef730655706c5a1df1edbc2 # v2.3.8
Score breakdown
Security (35%)50
Popularity (20%)43
Maintenance (30%)96
Reliability (15%)70