CI/CD supply chain security scanner for GitHub Actions — source-to-sink injection, AI agent config poisoning, steganography, compromised package detection, batch scanning, and auto-fix.
Stars
12
Forks
3
Watchers
12
Open Issues
2
Overall repository health assessment
No package.json found
This might not be a Node.js project
64
commits
Fix architecture diagram: show data flow, align boxes, add all capabilities
95f317bView on GitHubFix architecture diagram: show all capabilities, align boxes, supply chain scanner title
974c953View on GitHubRestructure README: badges, architecture diagram, install first, education last
dc59052View on GitHubFix README: correct rule references, campaign count, signatures path, remove nonexistent demo --list, update About
1f4b3a2View on GitHubAdd interactive menu, batch scan, and check-deps demo GIFs to README
b222dc1View on GitHubfeat: Phase 3 - dependency checking for known compromised packages
d80646cView on GitHubBump version to 2.7.0, update README with batch scanning docs
c9c54b9View on GitHubUpdate README: permissions-aware severity, vigilantdefense.com domain
ff07f1bView on GitHub