squid-protocol/GitGalaxy Scanner
Repo intelligence for humans and AI, without compilation: architecture mapping, risk scoring, and SBOM/SARIF generation for zero-trust CI/CD — SARIF output is ready for upload to security dashboard.
View on GitHubTrust Signals
- Scorecard Score
- not yet scored
- Maintenance Recency
- Stale
- License
- None
Inputs
| name | description | required | default |
|---|---|---|---|
| tool | The GitGalaxy command to execute. Options: galaxyscope, blast, vault-sentinel, supply-chain-firewall, xray-inspector, pii-leak-hunter, terabyte-log-scanner, api-network-map. (Note: SARIF and SBOM generation are now native to galaxyscope). | yes | galaxyscope |
| target | The directory or file path to scan. | yes | . |
| args | Additional CLI arguments to pass to the tool (e.g., --sarif-only, --sbom-only, --fail-on-secrets, --fail-on-malware, --max-systemic-threat 150.0). | no | "" |
| version | The version of GitGalaxy to install from PyPI. Defaults to latest. | no | latest |
| full_precision | Opt-in to install heavy physics engines (networkx, tiktoken, xgboost) for Blast Radius and ML Threat Inference. | no | false |
Outputs
no outputs