Skip to content

Supply chain: Actions workflow audit #10

Description

@martian56

Audit GitHub Actions usage across repositories.

  • Parse workflows and flag unpinned actions, broad permissions, and missing OIDC
  • Compute a risk score per workflow
  • Endpoint, scan workers, and tests

Metadata

Metadata

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions