Launching today

PipeAudit
Audit your GitHub Actions pipelines. Get a score.
5 followers
Audit your GitHub Actions pipelines. Get a score.
5 followers
Most teams never audit their CI/CD pipelines until something breaks. PipeAudit scans your GitHub Actions workflows and gives a score out of 100 based on 14 security and best practice rules : unrestricted token permissions, unpinned actions, missing dependency scans, jobs without timeouts, and more. Each issue comes with a concrete fix. Free to get started.






Ran it on one of my repos and the unpinned actions flag caught three I had no idea were floating on mutable tags. Super useful, will audit the rest this week.
@melike1ksm That's exactly the kind of thing PipeAudit is built to catch, mutable tags are easy to miss when you're focused on shipping. Let me know how the rest of the audits go this week!
honestly the scoring system out of 100 is such a nice touch, makes it feel way more tangible than just a vague pass/fail thing. love that each issue comes with an actual fix too, basically cuts out the guesswork.
@melikeelikehrw Thank you! That was a core design decision, a score makes it immediately clear where you stand instead of leaving you with a list of warnings to interpret. Glad it lands well.