How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Zizmor is a security linter and static analysis tool designed to audit GitHub Actions workflow files. It functions as a CI/CD security scanner that identifies security vulnerabilities, misconfigurations, and software supply chain risks within automation pipelines. The project distinguishes itself by providing an automated workflow remediator that applies security fixes to identified vulnerabilities. It also implements a language server for integration with code editors and supports a variety of analysis personas to scale the sensitivity and volume of reported findings. The tool covers a broa
Gato-X is a FAST scanning and attack tool for GitHub Actions pipelines. You can use it to identify Pwn Requests, Actions Injection, TOCTOU Vulnerabilities, and Self-Hosted Runner takeover at scale using just a single API token. It will also analyze cross-repository workflows and reusable…
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
GitHub Actions Pipeline Enumeration and Attack Tool
The main features of praetorian-inc/gato are: Attack and Audit Toolkits, Exploitation Frameworks, Git Repository Analysis.
Projects with overlapping indexed features include: arthaud/git-dumper. zizmorcore/zizmor — Zizmor is a security linter and static analysis tool designed to audit GitHub Actions workflow files. It functions as… adnanekhan/gato-x — Gato-X is a FAST scanning and attack tool for GitHub Actions pipelines. You can use it to identify Pwn Requests,… archerysec/archerysec — ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec. b1ack0wl/vulnerability-write-ups. accenture/jenkins-attack-framework — Jenkins Attack Framework.