Skip to content
#

sarif-report

Here are 21 public repositories matching this topic...

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

  • Updated Dec 6, 2025
  • TypeScript

Improve this page

Add a description, image, and links to the sarif-report topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the sarif-report topic, visit your repo's landing page and select "manage topics."

Learn more