Runseal - Supply Chain Security Action
Actively maintainednolabs-ai/runseal · Apache-2.0
Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.
★ 56 starsLast commit 28 days agoLatest v0.3.3
C
64
/ 100
Security signals
OpenSSF ScorecardNo data
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record
How to use it safely
Recommended: pin to commit SHA
uses: nolabs-ai/runseal@52e34e0aee4296180d4f80eb85621ca18314f31a # v0.3.3Mutable tags like v0.3.3 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.
Full workflow example
steps: - uses: nolabs-ai/runseal@52e34e0aee4296180d4f80eb85621ca18314f31a # v0.3.3
Score breakdown
Security (35%)50
Popularity (20%)30
Maintenance (30%)100
Reliability (15%)70