gha-audit is a command-line tool that scans GitHub Actions workflow files for common security issues including unpinned actions, pwn requests, script injection, and overly broad permissions. It helps developers and security teams identify and remediate supply-chain vulnerabilities in CI/CD pipelines. Built as a Python package with an MIT license, it is intended for integration into development and security workflows.
gha-audit is an Other dev tools project. Manually reviewing GitHub Actions workflows for supply-chain security issues and misconfigurations. gha-audit is an open-source project aimed at developers. gha-audit is open source under the MIT license. It runs on the command line.
Hiro-012 builds and maintains gha-audit, and it first shipped in 2026. The project is developed in the open on GitHub with 1 commit in the last 90 days. Key capabilities include Static Analysis, Security Audit, and Workflow Scanning.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do