Skip to content
View johnbillion's full-sized avatar

Sponsors

Sponsoring

@shivammathur
@ondrejmirtes
@itsgoingd
@sebastianbergmann
@derickr
@szepeviktor

Organizations

@WordPress @humanmade @wp-hooks @crontrol

Block or report johnbillion

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

GitHub Actions security

34 repositories

CI/CD Security Analyzer

Python 739 45 Updated Feb 24, 2025

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Shell 26 Updated Oct 28, 2024

Scans your Github Actions for security issues

JavaScript 112 14 Updated May 30, 2026

Octoscan is a static vulnerability scanner for GitHub action workflows.

Go 267 22 Updated Mar 30, 2026

:octocat: Static checker for GitHub Actions workflow files

Go 3,910 227 Updated Apr 19, 2026

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

TypeScript 1,173 103 Updated May 25, 2026

Static analysis for GitHub Actions

Rust 5,427 211 Updated May 30, 2026

poutine, a supply chain vulnerability scanner for build pipelines

Go 467 39 Updated May 26, 2026
TypeScript 506 112 Updated May 11, 2026

Anchore container analysis and scan provided as a GitHub Action

JavaScript 283 90 Updated May 29, 2026

GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.

Python 537 50 Updated May 27, 2026

A vulnerability scanner for container images and filesystems

Go 12,310 801 Updated May 29, 2026

How GitHub Actions workflows can be hacked

Shell 183 16 Updated Aug 23, 2024

A GitHub action that performs static analysis for shell scripts using shellcheck, shfmt and checkbashisms.

Shell 154 16 Updated Jan 4, 2026

A CLI that update GitHub Actions's `permissions` automatically

TypeScript 70 8 Updated Dec 8, 2025

Docker Scout GitHub Action

JavaScript 137 52 Updated May 19, 2026

Guideline of best practices to follow to configure Github Enterprise Cloud self-hosted runners in a secure way.

87 7 Updated Feb 23, 2024

Pin your GitHub actions to a specific hash

JavaScript 174 18 Updated Apr 11, 2026

A curated list of awesome things related to securing your GitHub Actions workflows.

37 5 Updated May 26, 2026

Official GitHub Action for OpenSSF Scorecard.

Go 380 85 Updated May 26, 2026

SARIF Microsoft Visual Studio Code extension

TypeScript 135 60 Updated Feb 14, 2026

Detect and remediate misconfigurations and security risks across all your GitHub and GitLab assets

Go 872 77 Updated Mar 28, 2025

Runtime Security Solution for your CI/CD Pipeline

JavaScript 122 9 Updated May 20, 2026

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.

Python 358 22 Updated Apr 21, 2026

A GitHub Action used for publishing an Action to ghcr.io as an OCI container.

TypeScript 122 15 Updated Aug 8, 2025

Supply Chain Security Research - Living Off The Pipeline tools

HTML 151 14 Updated May 7, 2026

GitHub Actions Cache Native Malware - for Educational and Research Purposes only.

TypeScript 158 12 Updated May 8, 2026

Orchestrate GitHub Actions Security

Go 325 52 Updated May 28, 2026

GitHub token permissions Monitor and Advisor actions

Python 368 26 Updated Jan 31, 2026

Script to audit GitHub Action Workflow files for potential vulnerabilities.

Python 152 18 Updated Aug 28, 2024