ActionRank

Commit Comment

Actively maintained

peter-evans/commit-comment · MIT

A GitHub action to create a comment for a commit on GitHub

99 starsLast commit 14 days agoLatest v4.0.0
C
56
/ 100
Security 45Maintenance 75Popularity 37Reliability 70

Security signals

OpenSSF Scorecard4.2 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: peter-evans/commit-comment@f6d60c65d05bb59f750fa51ad3de1d443ba0eb52 # v4.0.0

Mutable tags like v4.0.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: peter-evans/commit-comment@f6d60c65d05bb59f750fa51ad3de1d443ba0eb52 # v4.0.0

Score breakdown

Security (35%)45
Popularity (20%)37
Maintenance (30%)75
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for Commit Comment
Markdown
[![ActionRank](https://actionrank.dev/api/badge/peter-evans-commit-comment)](https://actionrank.dev/actions/peter-evans-commit-comment)
HTML version
HTML
<a href="https://actionrank.dev/actions/peter-evans-commit-comment"><img src="https://actionrank.dev/api/badge/peter-evans-commit-comment" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for Commit Comment

We'll email you only if Commit Comment becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address