Enables policy-driven vetting of open source dependencies within GitHub workflows to actively protect against vulnerabilities and malicious components.
Vet Action integrates the 'vet' tool into your GitHub workflow, providing active protection against vulnerable, outdated, unpopular, and potentially malicious open-source dependencies. By leveraging policy-as-code guardrails, it helps ensure the security and reliability of your software supply chain. It supports integration with SafeDep Cloud for enhanced features like malicious package analysis, and generates SARIF reports compatible with GitHub Code Scanning.