Skip to content

Supply chain: Actions workflow audit #10

@martian56

Description

@martian56

Audit GitHub Actions usage across repositories.

  • Parse workflows and flag unpinned actions, broad permissions, and missing OIDC
  • Compute a risk score per workflow
  • Endpoint, scan workers, and tests

Metadata

Metadata

Labels

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions