ActionRank

Composer (php-actions)

Stale

php-actions/composer

Use the Composer CLI in your Github Actions.

198 starsLast commit 7 months agoLatest v6.1.2
D
41
/ 100
Security 36Maintenance 25Popularity 49Reliability 76

Security signals

OpenSSF Scorecard2.6 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: php-actions/composer@8a65f0d3c6a1d17ca4800491a40b5756a4c164f3 # v6.1.2

Mutable tags like v6.1.2 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: php-actions/composer@8a65f0d3c6a1d17ca4800491a40b5756a4c164f3 # v6.1.2

Score breakdown

Security (35%)36
Popularity (20%)49
Maintenance (30%)25
Reliability (15%)76

Add this badge to your README

ActionRank grade badge for Composer (php-actions)
Markdown
[![ActionRank](https://actionrank.dev/api/badge/php-actions-composer)](https://actionrank.dev/actions/php-actions-composer)
HTML version
HTML
<a href="https://actionrank.dev/actions/php-actions-composer"><img src="https://actionrank.dev/api/badge/php-actions-composer" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for Composer (php-actions)

We'll email you only if Composer (php-actions) becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address