insecure-tree is an open-source CLI tool that audits the security posture of Python dependency trees, focusing on GitHub Actions workflows. It helps DevSecOps teams identify and mitigate supply chain risks in CI/CD pipelines.
insecure-tree sits in PulseGate's Security & compliance platforms category. Helping developers audit and improve the security of their Python dependencies in CI/CD pipelines using GitHub Actions. insecure-tree is an open-source project aimed at devsecops engineers. insecure-tree is open source under the MIT license. It ships for the command line.
Behind insecure-tree is Matthew Dean Martin, and it first shipped in 2026. The project is developed in the open on GitHub with 23 commits in the last 90 days. Key capabilities include dependency auditing, GitHub Actions integration, and security posture analysis.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match