Skip to content

Malicious Package in PR Should Fail Workflow #109

@abhisek

Description

@abhisek

Steps to reproduce

  • Integrate vet-action with your repo (eg. npm based project)
  • Do not configure API key to ensure vet uses Query Mode
  • Raise a PR to add a known malicious package

Expected behaviour:

  • vet should flag the malicious package in PR comment
  • vet GHA workflow should fail

cc: @n1lanjan

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions