Open Source Project Security Baseline Scanner
Version updated for https://github.com/revanite-io/osps-baseline-action to version v1.3.2.
- This action is used across all versions by 25 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
This GitHub Action automates security assessments for repositories, evaluating them against the Open Source Project Security Baseline (OSPS) controls. It generates reports in YAML, JSON, or SARIF formats, with the option to upload SARIF results directly to GitHub’s Security tab for centralized tracking. This action simplifies the process of identifying and addressing security issues, enhancing repository compliance and visibility.
Release notes
Changelog
- chore: Update ospo-reusable-workflows to new GitHub org @jmeridth (#15)
🧰 Maintenance
- chore(deps): pin pvtr-github-repo-scanner to v0.22.0 with SHA digest @jmeridth (#21)
- chore(deps): bump the dependencies group with 4 updates @dependabot[bot] (#20)
- chore(deps): bump the dependencies group with 4 updates @dependabot[bot] (#19)
- chore(deps): bump github/codeql-action from 4.32.5 to 4.32.6 in the dependencies group @dependabot[bot] (#16)
- chore(deps): bump github/codeql-action from 4.32.4 to 4.32.5 in the dependencies group @dependabot[bot] (#14)
- chore(deps): bump github/codeql-action from 4.32.3 to 4.32.4 in the dependencies group @dependabot[bot] (#13)
See details of all code changes since previous release