ActionRank

coverage.py badge

Stale

tj-actions/coverage-badge-py · MIT

:octocat: Github action to generate coverage badge without uploading results to a 3rd party.

70 starsLast commit 11 months agoLatest v2.0.4
D
42
/ 100
Security 42Maintenance 25Popularity 38Reliability 80

Security signals

OpenSSF Scorecard3.7 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: tj-actions/coverage-badge-py@1788babcb24544eb5bbb6e0d374df5d1e54e670f # v2.0.4

Mutable tags like v2.0.4 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: tj-actions/coverage-badge-py@1788babcb24544eb5bbb6e0d374df5d1e54e670f # v2.0.4

Score breakdown

Security (35%)42
Popularity (20%)38
Maintenance (30%)25
Reliability (15%)80