Below you will find pages that utilize the taxonomy term “Mlab-Sh”
August 28, 2026
postmortem supply-chain gate
Version updated for https://github.com/mlab-sh/postmortem to version v2.3.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is an all-in-one supply-chain security scanner for modern software projects that inspects dependencies across multiple ecosystems and flags potential compromises like malicious install scripts, typosquats, and compromised maintainers. It provides reputation intelligence, audit your machine, and deep source inspection, all while ensuring no telemetry or network communication unless explicitly requested.
August 26, 2026
postmortem supply-chain gate
Version updated for https://github.com/mlab-sh/postmortem to version v2.3.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is a fast, static analysis tool designed to detect potential supply-chain attacks by examining dependencies across various package managers. It provides reputation intelligence, vulnerability checks, and audit capabilities to ensure the integrity of your software supply chain. The action runs network requests only when necessary, ensuring minimal overhead and privacy.
August 16, 2026
postmortem supply-chain gate
Version updated for https://github.com/mlab-sh/postmortem to version v2.1.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary postmortem is a command-line tool designed to detect and analyze security threats in dependencies. It provides a comprehensive analysis of your project’s codebase to identify malicious activities such as supply-chain attacks, typosquats, and unverified sources. The action does not collect any telemetry and only queries the network when necessary, ensuring minimal overhead. It can score dependencies by their reputations across multiple platforms and detect known vulnerabilities in the ecosystem.
August 5, 2026
postmortem supply-chain gate
Version updated for https://github.com/mlab-sh/postmortem to version v2.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The postmortem action performs offline static analysis of dependencies across multiple ecosystems (npm, pip, poetry, Cargo, Go, Java, and NuGet) to detect potential security vulnerabilities and malicious code. It can also audit the system’s installed packages and provide reputation intelligence on dependencies. The action is designed to be offline by default and can be configured to run online for additional details such as known vulnerabilities.