🛡️ octoscope 0.38 answers one question for your whole account: is anything of mine compromised?

The supply-chain scan used to work one repository at a time, from the dashboard. If a worm had pushed an implant into one of your 90 repos, you'd have had to open them one by one to find out.

Now one command does the round:

octoscope --scan

It reads the default branch of every repository you own, plus everything in your watch list (so your organisations' repos come along), and prints one report: how many are clean, which ones look suspicious and why, and which ones it couldn't read. About 17 seconds for ~100 repos on my account.

Add --json and the same report becomes a versioned contract you can pipe into a nightly job.

The drill-ins grew too: a repo now shows its traffic (views and clones over 14 days) and its open Dependabot alerts, and a PR that's a layer of a stacked pull request shows the whole stack, with a 2/4 marker in the PRs list.

The detail I enjoyed most: the first sweep flagged two of my own repos as forged, because my release workflow commits as github-actions[bot] and pushes with git, which GitHub doesn't sign. Instead of trusting the bot, the scan now looks at who recently changed each file that can actually run code. A workflow updating a data file is a note; a bot commit that changed a hook still scores. Codex broke the first two versions of that rule before it held.

And a repository the scan can't read is never counted as clean: it's listed as not scanned, with the reason. In a security tool, the expensive mistake is the quiet one.

brew upgrade gfazioli/tap/octoscope

How do you check your repos today after a token leak or a scare like Shai-Hulud? Do you sweep everything, or only what you remember owning? 👇

Site:

Newsletter:

Discord:

11 views

Add a comment

Replies

Be the first to reply

Have a question or a thought to share? Add a comment above to start the conversation.