gha-audit
PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 4 Aug 2026. How this is checked
gha-audit is a command-line tool that scans GitHub Actions workflow files for common security issues including unpinned actions, pwn requests, script injection, and overly broad permissions. It helps developers and security teams identify and remediate supply-chain vulnerabilities in CI/CD pipelines. Built as a Python package with an MIT license, it is intended for integration into development and security workflows.
Inferred · not functionally tested
Overview
4 featuresPurpose: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations.
Inferred · not functionally tested
Audience: developers
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
gha-audit is a Static analysis & linters project. Inferred · not functionally tested: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations. Inferred · not functionally tested: gha-audit is an open-source project aimed at developers. Basis unknown · not verified: gha-audit is open source under the MIT license. Basis unknown · not verified: It runs on the command line.
Hiro-012 builds and maintains gha-audit, and it first shipped in 2026. The project is developed in the open on GitHub with 1 commit in the last 90 days. Inferred · not functionally tested: Key capabilities include Static Analysis, Security Audit, and Workflow Scanning.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- Static Analysis
- Security Audit
- Workflow Scanning
- Misconfiguration Detection
Topics: Inferred · not functionally tested
Built with & integrations
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
Frequently asked questions about gha-audit
- What is gha-audit?
- Inferred · not functionally tested: Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations. It is catalogued under Static analysis & linters on PulseGate.
- Who should use gha-audit?
- Inferred · not functionally tested: gha-audit is an open-source project built for developers.
- Is gha-audit free?
- Basis unknown · not verified: Yes — gha-audit is open source under the MIT license and free to use.
- What platforms does gha-audit run on?
- Basis unknown · not verified: gha-audit runs on the command line.
- Is gha-audit still active?
- PulseGate's liveness check found it on 14 Sep 2026. Its GitHub repository shows 1 commit in the last 90 days.
- What are alternatives to gha-audit?
- Similar projects tracked by PulseGate include gha-validator, gha-workflow-linter, and gh-audit.gha-validatorgha-workflow-lintergh-audit
- Who develops gha-audit?
- gha-audit is developed by Hiro-012.
- When did gha-audit launch?
- gha-audit first shipped in 2026.
Similar projects
Closest matches by what these projects do