npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

gha-security-checks

v0.4.0

Published

Reusable security audit engine for GitHub Actions and CI workflows.

Downloads

16

Readme

GHA Security Checks

Reusable security audit checks for GitHub Actions and CI workflows.

The project is built as a TypeScript library, CLI, and Docker-backed GitHub Action. The default mode is audit, which reports findings without failing CI.

Checks

  • PHP Composer vulnerabilities via composer audit
  • PHP Composer outdated and abandoned packages
  • Node.js npm vulnerabilities via npm audit
  • Node.js outdated packages via npm outdated
  • OSV-Scanner vulnerability results when osv-scanner is available
  • Secret and sensitive-file checks
  • GitHub Actions workflow hardening checks
  • JSON, Markdown, and SARIF reports
  • Pull request comment, job summary, and annotations

GitHub Action

permissions:
  contents: read
  pull-requests: write
  issues: write
  security-events: write

steps:
  - uses: actions/checkout@v4
  - uses: lavluda/[email protected]
    with:
      mode: audit
      comment: true
      summary: true
      annotations: true

The action pulls the published GHCR image for the release version, so consumer workflows do not rebuild the container on every run. Composer, npm, and OSV-Scanner are included in the container.

CLI

npx gha-security-checks --mode audit

Policy Modes

  • audit: report only
  • warn: report and annotate only
  • fail-on-high: fail on high or critical findings
  • fail-on-critical: fail only on critical findings
  • strict: fail on medium or higher findings, secrets, and workflow risks
  • custom: use failOn settings from config

Config

Copy gha-security-checks.example.yml to one of:

  • gha-security-checks.yml
  • gha-security-checks.yaml
  • .gha-security-checks.yml
  • .gha-security-checks.yaml

Example:

mode: audit

scanners:
  php: true
  node: true
  osv: true
  secrets: true
  githubActions: true

outputs:
  json: security-results.json
  markdown: security-summary.md
  sarif: security-results.sarif
  githubSummary: true
  prComment: true
  annotations: true