pipeline-check is an open-source command-line tool that scans CI/CD pipelines and infrastructure-as-code (IaC) configurations for security vulnerabilities. It supports platforms like GitHub Actions, GitLab CI, Terraform, and Kubernetes, providing checks against the OWASP CI/CD Top 10. Designed for DevSecOps teams to improve pipeline security.
pipeline-check sits in PulseGate's Code review & quality category. It focuses on detecting and mitigating security vulnerabilities in CI/CD pipelines and infrastructure-as-code configurations. pipeline-check is an open-source project aimed at devops engineers and security teams. pipeline-check is open source under the MIT license. pipeline-check is available on the command line, and it can be self-hosted.
It is developed by dmartinochoa, and it first shipped in 2026. Development happens publicly on GitHub with 1.6k commits in the last 90 days. Among its 9 catalogued features are CI/CD scanning, iaC security, and OWASP Top 10 checks.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Closest matches by what these projects do