Capabilities

GitHub Actions

GitHub Actions package analysis and vulnerability scanning capabilities

Package analysis

Cataloger + EvidenceLicenseDependenciesPackage Manager Claims
DepthEdgesKindsFilesDigestsIntegrity Hash
github-action-workflow-usage-cataloger
.github/workflows/*.yaml, .github/workflows/*.yml
github-actions-usage-cataloger
.github/actions/*/action.yml, .github/actions/*/action.yaml
github-actions-usage-cataloger
.github/workflows/*.yaml, .github/workflows/*.yml

Vulnerability scanning

Data SourceDisclosuresFixesTrack by
Source
Package
AffectedDateVersionsDate
GitHub Security Advisories (GHSA)

Next steps

Last modified November 26, 2025: allow local too invocation (d20d613)