Posts a web3 stack health comment on every PR that touches package.json or lockfiles.
- Runs
rightstack repo-audit --jsonagainst the PR branch - Posts (or updates) a comment with the stack health score, grade, and any critical/high/medium action items
- Only triggers on
package.json/ lockfile changes — no noise on unrelated PRs
- Copy
rightstack-audit.ymlto.github/workflows/in your repo - The action requires
pull-requests: writepermission (already set in the workflow) - No secrets needed — uses the default
GITHUB_TOKEN
Health score: 62/100 Grade: C
🔴 1 critical 🟠 1 high 🟡 2 medium
Detected tools: 8 | Repo:
my-dapp
Severity Tool Issue Fix CRITICAL Solana Kit Package has been renamed/migrated @solana/kitHIGH ElizaOS Experimental tool in stack — MEDIUM wagmi Package migration available wagmi@^2
rightstackmust be published to npm (npm install -g rightstack)- Node.js 20+
If rightstack isn't on npm yet, replace the install step with:
- name: Install RightStack (local)
run: |
cd /path/to/rightstack/apps/cli
npm install
npm linkOr use npx tsx src/index.ts if running from the monorepo.