Skip to content

Add Lazaretto Scan (dependency malware scanner GitHub Action)#115

Open
jamesdfinance-dev wants to merge 2 commits into
sottlmarek:masterfrom
jamesdfinance-dev:add-lazaretto-scan
Open

Add Lazaretto Scan (dependency malware scanner GitHub Action)#115
jamesdfinance-dev wants to merge 2 commits into
sottlmarek:masterfrom
jamesdfinance-dev:add-lazaretto-scan

Conversation

@jamesdfinance-dev

Copy link
Copy Markdown

Tool: Lazaretto Scan — https://github.com/jamesdfinance-dev/lazaretto-scan-action
Topic: OSS and Dependency management (software composition / supply-chain)
Why: A GitHub Action that scans your npm packages, repos, and skills for malicious behavior (known-bad indicators refreshed daily plus deterministic behavioral rules: credential theft, exfiltration, obfuscation, install scripts, prompt injection), not just known CVEs. It posts the verdict as a sticky PR comment and fails the build on a malicious verdict. Sits naturally next to Dependency Combobulator.
Maturity: released (v1.1.0), MIT-licensed action, actively maintained.
License: open source (MIT). Follows the table style with a stars badge.

jamesdfinance-dev and others added 2 commits July 17, 2026 16:50
Leads with what the action does and drops the trailing period to match
neighbouring rows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant