squid-protocol/GitGalaxy Scanner

Repo intelligence for humans and AI, without compilation: architecture mapping, risk scoring, and SBOM/SARIF generation for zero-trust CI/CD — SARIF output is ready for upload to security dashboard.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
toolThe GitGalaxy command to execute. Options: galaxyscope, blast, vault-sentinel, supply-chain-firewall, xray-inspector, pii-leak-hunter, terabyte-log-scanner, api-network-map. (Note: SARIF and SBOM generation are now native to galaxyscope). yesgalaxyscope
targetThe directory or file path to scan.yes.
argsAdditional CLI arguments to pass to the tool (e.g., --sarif-only, --sbom-only, --fail-on-secrets, --fail-on-malware, --max-systemic-threat 150.0).no""
versionThe version of GitGalaxy to install from PyPI. Defaults to latest.nolatest
full_precisionOpt-in to install heavy physics engines (networkx, tiktoken, xgboost) for Blast Radius and ML Threat Inference.nofalse

no outputs