Kevin JM

Kevin JM

Developer & founder · Building PipeAudit

About

Developer based in Paris. I build tools for developers and DevOps engineers. Currently building PipeAudit, a SaaS that audits GitHub Actions pipelines and gives a score out of 100 based on 14 security and best practice rules. Background in Python, FastAPI, Next.js, Rust, and application security.

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking

Maker History

  • PipeAudit
    PipeAuditAudit your GitHub Actions pipelines. Get a score.
    Jul 2026
  • 🎉
    Joined Product HuntJuly 13th, 2026

Forums

🔐 Trust update: PipeAudit now uses a GitHub App

The previous OAuth flow showed "read and write access to all repositories", the smallest OAuth scope available, but understandably scary. Several people reached out saying they backed out at that screen.

We've migrated to a GitHub App. GitHub now shows "Read access to code and metadata", the minimum possible access to analyze your workflow files.

If that was your blocker, it's gone. Give it a try: pipeaudit.dev

2mo ago

PipeAudit - Audit your GitHub Actions pipelines. Get a score.

Most teams never audit their CI/CD pipelines until something breaks. PipeAudit scans your GitHub Actions workflows and gives a score out of 100 based on 14 security and best practice rules : unrestricted token permissions, unpinned actions, missing dependency scans, jobs without timeouts, and more. Each issue comes with a concrete fix. Free to get started.
View more