Continuously watches your GitHub Actions, GitLab CI, and Bitbucket Pipelines for dangerous behavioral changes — the kind that lets attackers smuggle malicious steps, gain privileged tokens, or hijack your runners.
Free for open-source. No credit card required.
Trusted by security-conscious teams
Modern supply-chain attacks don't look like "leaked AWS key." They look like:
pull_request_target to gain write tokens for forked-PR coderuns-on: self-hosted giving outside code access to your runneractions/checkout@v4 swapped to a fork by SHA pin removal@main (mutable, hijackable)pip install --extra-index-url (dependency confusion seed)30+ security rules mapped to OWASP CICD Top 10, continuously monitoring your pipeline configurations for drift.
Every PR with CI changes gets a security check with inline annotations and severity badges. Block dangerous changes before merge.
Compares against your known-good baseline. Get alerted when CI behavior changes, not just when code changes.
From pull_request_target exploitation to unpinned actions, cache poisoning, and script injection — all mapped to OWASP CICD Top 10.
Auto-generate SLSA L2/L3 evidence packs and provenance attestations for your build pipelines.
One-click fixes for trivially fixable issues: add permissions blocks, pin actions to SHAs, add timeouts.
Every Monday, get a risk summary of all your repos. Track your security posture over time.
A sample of our 30+ security rules, each mapped to OWASP CICD Top 10
CICD-SEC-4CICD-SEC-3CICD-SEC-4CICD-SEC-9CICD-SEC-3CICD-SEC-3CICD-SEC-2CICD-SEC-3CICD-SEC-3CICD-SEC-9CICD-SEC-4CICD-SEC-2Free for open source. Scales with your team.
For public repositories
For small teams
For security teams
Need more? Contact us for Enterprise pricing with SSO, unlimited repos, and on-prem runners.
Install in 30 seconds. First scan results in under a minute. No configuration needed.
Install GitHub App