It scans your npm packages, repos, or skills for malicious behavior (known-bad indicators refreshed daily plus deterministic behavioral rules), posts a verdict comment on the pull request, and fails the build on a malicious verdict. Open source (MIT), released, and documented with a quick start. Fits alongside the other dependency-security actions in that section.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.
## 📋 Pull Request Information
**Original PR:** https://github.com/sdras/awesome-actions/pull/852
**Author:** [@jamesdfinance-dev](https://github.com/jamesdfinance-dev)
**Created:** 7/17/2026
**Status:** 🔄 Open
**Base:** `main` ← **Head:** `add-lazaretto-scan`
---
### 📝 Commits (1)
- [`beb0acb`](https://github.com/sdras/awesome-actions/commit/beb0acb8314b26b3be2396fd37089562b78f684d) Add Lazaretto Scan to Security
### 📊 Changes
**1 file changed** (+1 additions, -0 deletions)
<details>
<summary>View changed files</summary>
📝 `README.md` (+1 -0)
</details>
### 📄 Description
Adds [lazaretto-scan-action](https://github.com/jamesdfinance-dev/lazaretto-scan-action) under Community Resources -> Security.
It scans your npm packages, repos, or skills for malicious behavior (known-bad indicators refreshed daily plus deterministic behavioral rules), posts a verdict comment on the pull request, and fails the build on a malicious verdict. Open source (MIT), released, and documented with a quick start. Fits alongside the other dependency-security actions in that section.
---
<sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
📋 Pull Request Information
Original PR: https://github.com/sdras/awesome-actions/pull/852
Author: @jamesdfinance-dev
Created: 7/17/2026
Status: 🔄 Open
Base:
main← Head:add-lazaretto-scan📝 Commits (1)
beb0acbAdd Lazaretto Scan to Security📊 Changes
1 file changed (+1 additions, -0 deletions)
View changed files
📝
README.md(+1 -0)📄 Description
Adds lazaretto-scan-action under Community Resources -> Security.
It scans your npm packages, repos, or skills for malicious behavior (known-bad indicators refreshed daily plus deterministic behavioral rules), posts a verdict comment on the pull request, and fails the build on a malicious verdict. Open source (MIT), released, and documented with a quick start. Fits alongside the other dependency-security actions in that section.
🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.