Open Source Project Security Baseline Scanner
Version updated for https://github.com/revanite-io/osps-baseline-action to version v1.3.4.
- This action is used across all versions by 33 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
The GitHub Action for OSPS Baseline automates security assessments against the Open Source Project Security Baseline by running predefined controls on a GitHub repository. It outputs results in YAML, JSON, or SARIF format, allowing users to integrate assessment reports into their CI/CD pipelines and automatically upload them to GitHub’s Security tab as SARIF files.
What’s Changed
Changelog
🐛 Bug Fixes
- fix: bump pvtr scanner image to v0.28.0 @jmeridth (#45)
🧰 Maintenance
- chore(deps): bump the dependencies group across 1 directory with 3 updates @dependabot[bot] (#44)
- chore(deps): bump the dependencies group with 2 updates @dependabot[bot] (#42)
- chore(deps): bump the dependencies group with 5 updates @dependabot[bot] (#41)
- chore(deps): bump the dependencies group with 3 updates @dependabot[bot] (#39)
- chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 @dependabot[bot] (#40)
- chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2 in the dependencies group @dependabot[bot] (#38)
- chore(deps): bump the dependencies group with 2 updates @dependabot[bot] (#37)
- chore(deps): bump the dependencies group with 5 updates @dependabot[bot] (#36)
See details of all code changes since previous release