Skip to content
Back to the index

actionsec

PyPIInfrastructure

PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 30 Jun 2026. How this is checked

actionsec is an open-source CLI tool that scans GitHub Actions workflows for common security issues such as unpinned actions, script injection, and overly broad permissions. It is designed for DevOps engineers to improve CI/CD pipeline security with zero configuration and no dependencies.

Inferred · not functionally tested

Open SourceMITCLI
Visit PyPI

Overview

6 features

Purpose: Detecting and preventing security vulnerabilities in GitHub Actions workflows.

Inferred · not functionally tested

Audience: devops engineers

Inferred · not functionally tested

Functions: monitoring

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

actionsec is an Application security & vulnerability scanning project. Inferred · not functionally tested: It focuses on detecting and preventing security vulnerabilities in GitHub Actions workflows. Inferred · not functionally tested: actionsec is an open-source project aimed at devops engineers. Basis unknown · not verified: actionsec is open source under the MIT license. Basis unknown · not verified: It ships for the command line.

Behind actionsec is jjdoor, and it first shipped in 2026. Inferred · not functionally tested: Among its 6 catalogued features are security scanning, unpinned action detection, and script injection detection.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Security scanning
  • Unpinned action detection
  • Script injection detection
  • Broad permissions check
  • Zero config
  • No dependencies

Topics: Inferred · not functionally tested

Tags
github-actions-securityci-pipeline-scannerworkflow-audit

JSON profile · Text profile · Access guide

Built with & integrations

Connectors
github
Runs on
CLI

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tierGitHub

Indexing history

What PulseGate has recorded for this listing

Nothing recorded for this listing in this window.

Frequently asked questions about actionsec

What does actionsec do?
Inferred · not functionally tested: Actionsec focuses on detecting and preventing security vulnerabilities in GitHub Actions workflows. It is catalogued under Application security & vulnerability scanning on PulseGate.
Who should use actionsec?
Inferred · not functionally tested: actionsec is an open-source project built for devops engineers.
Is actionsec free?
Basis unknown · not verified: Yes — actionsec is open source under the MIT license and free to use.
What platforms does actionsec run on?
Basis unknown · not verified: actionsec runs on the command line.
Is actionsec still active?
PulseGate's liveness check found it on 14 Sep 2026.
What are alternatives to actionsec?
Similar projects tracked by PulseGate include actionaudit, gha-audit, and actions-warden.actionauditgha-auditactions-warden
Who makes actionsec?
actionsec is developed by jjdoor.
How long has actionsec been around?
actionsec first shipped in 2026.

Similar projects

Closest matches by what these projects do