{"id":50118599,"url":"https://github.com/step-security/edit-release","last_synced_at":"2026-05-23T17:02:57.992Z","repository":{"id":339786856,"uuid":"1163368723","full_name":"step-security/edit-release","owner":"step-security","description":"A GitHub Action for editing an existing release. Secure drop-in replacement for irongut/EditRelease.","archived":false,"fork":false,"pushed_at":"2026-05-21T18:59:42.000Z","size":73,"stargazers_count":0,"open_issues_count":10,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-21T23:25:01.186Z","etag":null,"topics":["step-security-maintained-actions"],"latest_commit_sha":null,"homepage":"https://docs.stepsecurity.io/actions/stepsecurity-maintained-actions","language":"C#","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/step-security.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-02-21T14:25:46.000Z","updated_at":"2026-05-21T18:57:27.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/step-security/edit-release","commit_stats":null,"previous_names":["step-security/editrelease","step-security/edit-release"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/step-security/edit-release","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fedit-release","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fedit-release/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fedit-release/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fedit-release/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/step-security","download_url":"https://codeload.github.com/step-security/edit-release/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/step-security%2Fedit-release/sbom","scorecard":{"id":1244041,"data":{"date":"2026-02-26T09:07:45Z","repo":{"name":"github.com/step-security/edit-release","commit":"f6f22f3f4f39a6044138ad9ddd2891702334ec75"},"scorecard":{"version":"v5.0.0","commit":"ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4"},"score":6.8,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#binary-artifacts"}},{"name":"Branch-Protection","score":8,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'main'","Info: 'force pushes' disabled on branch 'main'","Warn: required approving review count is 1 on branch 'main'","Warn: codeowners review is required - but no codeowners file found in repo","Info: status check found to merge onto on branch 'main'","Info: PRs are required in order to make changes on branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":10,"reason":"10 out of 10 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#ci-tests"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#cii-best-practices"}},{"name":"Code-Review","score":8,"reason":"Found 8/9 approved changesets -- score normalized to 8","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#code-review"}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#contributors"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dangerous-workflow"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: Dependabot: .github/dependabot.yml:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#dependency-update-tool"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#license"}},{"name":"Maintained","score":0,"reason":"project was created in last 90 days. please review its contents carefully","details":["Warn: Repository was created in last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#packaging"}},{"name":"Pinned-Dependencies","score":8,"reason":"dependency not pinned by hash detected -- score normalized to 8","details":["Warn: nugetCommand not pinned by hash: Dockerfile:4","Warn: nugetCommand not pinned by hash: .github/workflows/ci-build.yml:37","Info:  13 out of  13 GitHub-owned GitHubAction dependencies pinned","Info:  12 out of  12 third-party GitHubAction dependencies pinned","Info:   2 out of   2 containerImage dependencies pinned","Info:   0 out of   2 nugetCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 17 commits out of 23 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#sast"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#security-policy"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#signed-releases"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/actions_release.yml:16","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/actions_release.yml:18","Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:31","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:32","Info: jobLevel 'contents' permission set to 'read': .github/workflows/docker-linter.yml:25","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scorecards.yml:29","Info: jobLevel 'actions' permission set to 'read': .github/workflows/scorecards.yml:30","Info: jobLevel 'issues' permission set to 'read': .github/workflows/scorecards.yml:32","Info: jobLevel 'pull-requests' permission set to 'read': .github/workflows/scorecards.yml:33","Info: jobLevel 'checks' permission set to 'read': .github/workflows/scorecards.yml:35","Info: topLevel 'contents' permission set to 'read': .github/workflows/actions_release.yml:11","Info: topLevel 'packages' permission set to 'read': .github/workflows/auto_cherry_pick.yml:21","Warn: topLevel 'contents' permission set to 'write': .github/workflows/auto_cherry_pick.yml:19","Info: topLevel 'contents' permission set to 'read': .github/workflows/ci-build.yml:10","Info: topLevel 'contents' permission set to 'read': .github/workflows/claude_review.yml:14","Info: topLevel 'packages' permission set to 'read': .github/workflows/claude_review.yml:16","Info: topLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:24","Info: topLevel 'contents' permission set to 'read': .github/workflows/dependency-review.yml:13","Info: topLevel 'contents' permission set to 'read': .github/workflows/docker-linter.yml:18","Info: topLevel 'contents' permission set to 'read': .github/workflows/docker.yml:12","Warn: topLevel 'packages' permission set to 'write': .github/workflows/docker.yml:13","Info: topLevel permissions set to 'read-all': .github/workflows/scorecards.yml:18"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#token-permissions"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/ea7e27ed41b76ab879c862fa0ca4cc9c61764ee4/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2026-02-26T16:56:48.552Z","repository_id":339786856,"created_at":"2026-02-26T16:56:48.553Z","updated_at":"2026-02-26T16:56:48.553Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33404271,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-23T04:15:53.637Z","status":"ssl_error","status_checked_at":"2026-05-23T04:15:53.242Z","response_time":53,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["step-security-maintained-actions"],"created_at":"2026-05-23T17:02:53.413Z","updated_at":"2026-05-23T17:02:57.984Z","avatar_url":"https://github.com/step-security.png","language":"C#","funding_links":[],"categories":[],"sub_categories":[],"readme":"[![StepSecurity Maintained Action](https://raw.githubusercontent.com/step-security/maintained-actions-assets/main/assets/maintained-action-banner.png)](https://docs.stepsecurity.io/actions/stepsecurity-maintained-actions)\n\n# Edit Release\n\n\u003cdiv align=\"center\"\u003e\n\n![.NET 6.0](https://img.shields.io/badge/Version-.NET%206.0-informational?style=flat\u0026logo=dotnet)\n\u0026nbsp;\n![Built With Docker](https://img.shields.io/badge/Built_With-Docker-informational?style=flat\u0026logo=docker)\n\u0026nbsp;\n[![CI Build](https://github.com/step-security/edit-release/actions/workflows/ci-build.yml/badge.svg)](https://github.com/step-security/edit-release/actions/workflows/ci-build.yml)\n\u0026nbsp;\n\n\n\u003c/div\u003e\n\nA GitHub Action for editing an existing release. Edit the Name, Draft status and Pre-release status of a release as well as adding text and the content of markdown files to the Body of a release.\n\nEdit Release is compatible with [StepSecurity Secure Workflows](https://github.com/step-security/secure-workflows) and uses a Docker image that is cryptographically signed using [Sigstore](https://www.sigstore.dev/).\n\nAs a Docker based action Edit Release requires a Linux runner, see [Types of Action](https://docs.github.com/en/actions/creating-actions/about-custom-actions#types-of-actions).\n\n## Inputs\n\n#### `token`\n**Required**\n\nAuthentication token, use either `GITHUB_TOKEN` or a Personal Access Token.\n\n#### `id`\n**Required**\n\nThe id of the release to edit, e.g. `github.event.release.id`.\n\n#### `name`\n\nNew text for the name of the release.\n\n#### `replacename`\n\nSet `true` to replace the release name, `false` to add to the release name (default).\n\n#### `draft`\n\nSet `true` to change the release to a draft, `false` to publish the release. Omit if you do not want to change the draft status of the release.\n\n#### `prerelease`\n\nSet `true` to identify the release as a pre-release, `false` to identify the release as a full release. Omit if you do not want to change the status of the release.\n\n#### `body`\n\nNew text for the body of the release.\n\n#### `replacebody`\n\nSet `true` to replace the release body, `false` to add to the release body. (default)\n\n#### `files`\n\nA comma separated list of files whose content will be added after the release body text.\n\n#### `spacing`\n\nThe number of blank lines required between each addition to the release body. (default = 1)\n\n## Outputs\n\nEdit Release has no outputs other than console messages and the edited release.\n\n## Usage\n\n```yaml\nname: Edit Release\nuses: step-security/edit-release@v1\nwith:\n  token: ${{ secrets.GITHUB_TOKEN }}\n  id: ${{ github.event.release.id }}\n  name: \"Beta\"\n  prerelease: true\n  body: \"This is a pre-release version for testing purposes.\"\n  files: \"changelog.md,testcoverage.md\"\n```\n\n### Workflow Example\n\nThis workflow will run when you publish a release. It builds and tests a .Net 5 Nuget library before deploying it to GitHub Packages and adding a test coverage report to the release.\n\n```yaml\nname: Build + Deploy\n\non:\n  release:\n    types: [published]\n    branches: [master]\n\nenv:\n  GITHUB_PACKAGE_URL: 'https://nuget.pkg.github.com/${{ github.repository_owner }}/index.json'\n\njobs:\n  build:\n    runs-on: ubuntu-latest\n    name: Release Build\n    steps:\n    - name: Checkout\n      uses: actions/checkout@v6\n      with:\n        fetch-depth: 0\n\n    - name: Setup .NET\n      uses: actions/setup-dotnet@v5\n      with:\n        dotnet-version: 5.0.x\n\n    - name: Restore Dependencies\n      run: dotnet restore src/Example.sln\n\n    - name: Build\n      run: dotnet build src/Example.sln --configuration Release --no-restore\n\n    - name: Test\n      run: dotnet test src/Example.sln --configuration Release --no-build --verbosity normal --collect:\"XPlat Code Coverage\" --results-directory ./coverage\n\n    - name: Copy Test Details\n      run: cp coverage/**/coverage.cobertura.xml coverage/coverage.cobertura.xml\n\n    - name: Create Test Report\n      uses: irongut/CodeCoverageSummary@v1\n      with:\n        filename: coverage/coverage.cobertura.xml\n        badge: true\n        format: 'markdown'\n        output: 'both'\n\n    - name: Upload Nuget Artifact\n      uses: actions/upload-artifact@v6\n      with:\n        name: release-nuget\n        path: src/Example/bin/Release/Example.Library*.nupkg\n\n    - name: Upload Test Report Artifact\n      uses: actions/upload-artifact@v6\n      with:\n        name: release-nuget\n        path: code-coverage-results.md\n\n  deploy:\n    name: Deploy to GitHub Packages\n    needs: [build]\n    runs-on: ubuntu-latest\n    steps:\n    - name: Download Artifacts\n      uses: actions/download-artifact@v7\n      with:\n        name: release-nuget\n\n    - name: Setup Nuget\n      uses: NuGet/setup-nuget@v2\n      with:\n        nuget-version: latest\n\n    - name: Add GitHub package source\n      run: nuget sources Add -Name GitHub -Source ${{env.GITHUB_PACKAGE_URL}} -UserName ${{ github.repository_owner }} -Password ${{ secrets.GITHUB_TOKEN }}\n\n    - name: Push to GitHub Packages\n      run: nuget push **/*.nupkg -source GitHub -SkipDuplicate\n\n    - name: Add Test Report to Release\n      uses: step-security/edit-release@v1\n      with:\n        token: ${{ secrets.GITHUB_TOKEN }}\n        id: ${{ github.event.release.id }}\n        body: \"Released to GitHub Packages.\"\n        files: \"code-coverage-results.md\"\n```\n\n## License\n\nEdit Release Action is available under the MIT license, see the [LICENSE](LICENSE) file for more info.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstep-security%2Fedit-release","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fstep-security%2Fedit-release","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fstep-security%2Fedit-release/lists"}