step-security/npm-get-version-action

step-security/npm-get-version-action

This Action scans for a package.json file and reads the version number from that.

GitHubGitHub Repository

0 stars

Docker

Docker Action

Maintained by StepSecurity

Score updated 5 days ago

GitHub Actions security score comparison

step-security/npm-get-version-actionmartinbeentjes/npm-get-version-action

Score

10/10

0/10

License

MIT License

Maintained

Maintained by StepSecurity

Vulnerabilities

0 existing vulnerabilities detected

Docker vulnerabilities

docker://ghcr.io/step-security/npm-get-version-action:v1.3.4@sha256:4688393733bc980a004434c397d8791cbd1c6c8dd5fce6bdbdfea27e48d5e2e8

(2 existing vulnerabilities detected)

alpine:3.10

(1 existing vulnerabilities detected)

Branch protection

Branch protection is maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging-

Secure publishing

Reproducible builds with SBOM and provenance-

Signed commits

All commits are signed-

Automated security tools

Findings from tools are triaged and fixed before each change-

Popular

Used by StepSecurity enterprise customersUsed by 892 open-source projects

Security Policy

security policy file detectedsecurity policy file not detected