
Pipelineweft: CI Audit
Harden Workflow YAML
0 ratings
$2.99
Rating summary
About
Pipelineweft audits GitHub Actions workflow YAML for supply-chain risk — a scored security review of your CI pipeline that runs entirely on your device.
The workbench puts your workflow source and its audit report on one screen: side by side on iPad and other wide displays, one flip apart on iPhone. Edit the YAML in a monospaced editor, tap Run Audit, and the supply-chain posture report updates with a 0–100 score, a findings-by-severity chart, and every finding pinned to its line number with a concrete remediation.
WHAT IT CHECKS
• Actions pinned to tags instead of reviewed 40-character commit SHAs
• Secrets interpolated directly into run: shell text
• Privileged pull_request_target triggers
• write-all token permissions
• Self-hosted runners receiving workflow code
• Missing explicit permissions block (implicit token scope)
FEATURES
• Monospaced YAML editor with autocorrection disabled
• Severity-weighted score — criticals cost more than warnings
• Findings sorted critical-first, each with line number and fix
• Findings-by-severity bar chart
• Executable step count (uses: and run:) at a glance
• Sample workflow included so you can explore every check immediately
PREMIUM BY DESIGN
One-time paid download. No account, no ads, no analytics, no tracking, and no network access at all — your workflow YAML never leaves the device. Works completely offline.
Show more
What's New in Pipelineweft
1.1
August 31, 2026
Pipelineweft now opens directly into a single fast audit workbench: your workflow YAML beside its scored supply-chain report — side by side on iPad, one flip apart on iPhone. Edit the source, tap Run Audit, and get a 0–100 score, a severity chart, and line-numbered findings with concrete remediations.
More
