postmortem supply-chain gate
Version updated for https://github.com/mlab-sh/postmortem to version v2.1.2.
- This action is used across all versions by 1 repositories.
Action Type
This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary
postmortem is a command-line tool designed to detect and analyze security threats in dependencies. It provides a comprehensive analysis of your project’s codebase to identify malicious activities such as supply-chain attacks, typosquats, and unverified sources. The action does not collect any telemetry and only queries the network when necessary, ensuring minimal overhead. It can score dependencies by their reputations across multiple platforms and detect known vulnerabilities in the ecosystem.
What’s Changed
Full Changelog: https://github.com/mlab-sh/postmortem/compare/v2.1.1...v2.1.2