igibek/Argus Action

Static analyzer for GitHub Actions workflow and third-party actions to detect code injection vulnerabilities.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
modeArgus supports two modes of operation. The "action" mode can be used to analyze the custom actions, the "repo" mode is used to analyze the repository workflowsyesrepo
workflowWorkflow to analyze. By default it will analyze all the workflows under .github/workflows folder. This maybe time consuming.no
referenceThe repository reference (branch, tag, commit) that will be used during scanno${{ github.sha }}

no outputs