Skip to content
Back to the index

gha-audit

PyPIInfrastructure

PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 4 Aug 2026. How this is checked

gha-audit is a command-line tool that scans GitHub Actions workflow files for common security issues including unpinned actions, pwn requests, script injection, and overly broad permissions. It helps developers and security teams identify and remediate supply-chain vulnerabilities in CI/CD pipelines. Built as a Python package with an MIT license, it is intended for integration into development and security workflows.

Inferred · not functionally tested

Open SourceMITCLI
Visit PyPI

Overview

4 features

Purpose: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations.

Inferred · not functionally tested

Audience: developers

Inferred · not functionally tested

Functions: Unknown

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

gha-audit is a Static analysis & linters project. Inferred · not functionally tested: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations. Inferred · not functionally tested: gha-audit is an open-source project aimed at developers. Basis unknown · not verified: gha-audit is open source under the MIT license. Basis unknown · not verified: It runs on the command line.

Hiro-012 builds and maintains gha-audit, and it first shipped in 2026. The project is developed in the open on GitHub with 1 commit in the last 90 days. Inferred · not functionally tested: Key capabilities include Static Analysis, Security Audit, and Workflow Scanning.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Static Analysis
  • Security Audit
  • Workflow Scanning
  • Misconfiguration Detection

Topics: Inferred · not functionally tested

Tags
github-actions-securitysupply-chain-auditci-securitystatic-analysisdevsecops

JSON profile · Text profile · Access guide

Built with & integrations

Runs on
CLI

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceGitHubActive maintenance

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed4 Aug · 07:11 UTC
    gha-audit seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about gha-audit

What is gha-audit?
Inferred · not functionally tested: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations. It is catalogued under Static analysis & linters on PulseGate.
Who should use gha-audit?
Inferred · not functionally tested: gha-audit is an open-source project built for developers.
Is gha-audit free?
Basis unknown · not verified: Yes — gha-audit is open source under the MIT license and free to use.
What platforms does gha-audit run on?
Basis unknown · not verified: gha-audit runs on the command line.
Is gha-audit still active?
PulseGate's liveness check found it on 14 Sep 2026. Its GitHub repository shows 1 commit in the last 90 days.
What are alternatives to gha-audit?
Similar projects tracked by PulseGate include gha-validator, gha-workflow-linter, and gh-audit.gha-validatorgha-workflow-lintergh-audit
Who develops gha-audit?
gha-audit is developed by Hiro-012.
When did gha-audit launch?
gha-audit first shipped in 2026.

Similar projects

Closest matches by what these projects do