A
licenseNot graded
qualityC
maintenanceEnables scanning GitHub Actions workflow YAML for real-world security vulnerabilities such as script injection from attacker-controlled expressions, unpinned third-party actions, missing permissions blocks, and dangerous pull_request_target checkouts. It returns each finding with its exact location, an explanation of the risk, and a concrete remediation.
MIT