magpie-workflow-security-audit
Read-only GitHub Actions workflow security audit for one repository,
an explicit repository set, or a whole GitHub org. Runs zizmor to
surface injection vulnerabilities, excessive permissions, unpinned
external actions, and self-hosted-runner fork-secret leaks. Produces
a grouped, prioritised finding report; never edits workflow files,
opens PRs, or posts comments.
- License
- Apache-2.0
Pinned to revision e8c3a346a06a, so it is the text this page describes rather than whatever the author pushed since.
Files
Every link opens the file at its source, pinned to the revision this page describes.