Lima Networks
Audit GitHub Actions risk before workflows reach production
Scan workflow files for supply chain vulnerabilities, insecure triggers, unsafe permissions, and known CVEs with a clean browser-based review flow.
Coverage
What the auditor checks
Workflow exposure
Unsafe triggers, secret handling, runner usage, and permission scoping across workflow files.
Action trust
Mutable refs, unverified publishers, and setup action pinning issues across referenced actions.
Vulnerability intelligence
OSV-backed CVE lookups and AI-assisted repository summaries for faster remediation planning.
Workflow
How teams use it
Authenticate with GitHub
Access public and private repositories through the Worker without exposing tokens to frontend JavaScript.
Scan workflows
Use repository URLs, local YAML uploads, or pasted workflow content with the same rules engine.
Prioritise fixes
Review severity-ranked findings, AI analysis, and exportable reporting for remediation handoff.