step-security/npm-get-version-action

step-security/npm-get-version-action

This Action scans for a package.json file and reads the version number from that.

GitHubGitHub Repository

0 star

Docker

Docker Action

Maintained by StepSecurity

Score updated 6 days ago

GitHub Actions security score comparison

step-security/npm-get-version-actionmartinbeentjes/npm-get-version-action

Score

10/10

0/10

License

MIT License

Maintained

Maintained by StepSecurity

Vulnerabilities

0 existing vulnerabilities detected

Docker vulnerabilities

docker://ghcr.io/step-security/npm-get-version-action:v1.3.3@sha256:3666f9fdf5e99e3a48f1f2755b4ea33d529cdf6566a95ec0c0eba52bc10fba36

(7 existing vulnerabilities detected)

alpine:3.10

(1 existing vulnerabilities detected)

Branch protection

Branch protection is maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging-

Secure publishing

Reproducible builds with SBOM and provenance-

Signed commits

All commits are signed-

Automated security tools

Findings from tools are triaged and fixed before each change-

Popular

Used by StepSecurity enterprise customersUsed by 880 open-source projects

Security Policy

security policy file detectedsecurity policy file not detected