GitHub Actions Security Auditor

Lima Networks

Audit GitHub Actions risk before workflows reach production

Scan workflow files for supply chain vulnerabilities, insecure triggers, unsafe permissions, and known CVEs with a clean browser-based review flow.

8 rules Workflow security checks
OSV lookup Known vulnerable actions
Private repos OAuth-protected scanning

Coverage

What the auditor checks

Workflow exposure

Unsafe triggers, secret handling, runner usage, and permission scoping across workflow files.

Action trust

Mutable refs, unverified publishers, and setup action pinning issues across referenced actions.

Vulnerability intelligence

OSV-backed CVE lookups and AI-assisted repository summaries for faster remediation planning.

Workflow

How teams use it

01

Authenticate with GitHub

Access public and private repositories through the Worker without exposing tokens to frontend JavaScript.

02

Scan workflows

Use repository URLs, local YAML uploads, or pasted workflow content with the same rules engine.

03

Prioritise fixes

Review severity-ranked findings, AI analysis, and exportable reporting for remediation handoff.