R Package Validation Report
Staleinsightsengineering/thevalidatoR · MIT
Github Action that generates R Package Validation documentation 🏁
★ 64 starsLast commit 4 months agoLatest v2.0.5
D
52
/ 100
Security signals
OpenSSF Scorecard4.9 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: insightsengineering/thevalidatoR@4f7e5b12134fdf14f453016b3a3ebaa1d01be388 # v2.0.5Mutable tags like v2.0.5 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: insightsengineering/thevalidatoR@4f7e5b12134fdf14f453016b3a3ebaa1d01be388 # v2.0.5
Score breakdown
Security (35%)49
Popularity (20%)36
Maintenance (30%)57
Reliability (15%)70