Below you will find pages that utilize the taxonomy term “Lucashgrifoni”
August 25, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.17.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action evaluates OSS repositories against security policies and generates reports. It provides detailed evidence-based control verifications with a focus on assurance levels, helping developers ensure their projects meet security requirements before merging.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.17 Dependency and pipeline hygiene. No product behaviour changes – no control, report, schema, CLI flag or exit code moved. If you upgrade from v10.0.16, your verdicts will be identical.
August 15, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.15.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action evaluates OSS repositories against security policies using a policy library and generates reports in Markdown, JSON, and SARIF formats. It supports evidence files, waivers, and compliance frameworks like SLSA, OSPS, and SSDF. The action helps maintain code quality and ensures adherence to security standards by providing detailed reports on findings and control assessments.
August 8, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary oss-policy-kit is a tool that evaluates OSS repositories against security policies using local files and evidence, generating Markdown, JSON, and SARIF reports. It provides detailed assurance grades based on the type of verification (deterministic, signal, or evidence-backed) and supports various report formats for both human review and automation.