Security & DevSecOps
CI/CD workflow security linter
Scan a GitHub Actions or GitLab CI file for the pipeline failures that get exploited — script injection from pull request titles, unpinned actions, and pull_request_target building fork code.
The check worth knowing about is script injection: GitHub substitutes ${{ ... }} into your shell script before the shell runs it, so an expression carrying a pull request title or branch name is not a variable — it is source code written by whoever opened the PR. Passing the value through env: and quoting it makes it data again. This reads one file; it cannot see your branch protection, environment approvals or runner configuration, so a clean result is not an audit. Runs in your browser.
More in this category
These exist because the underlying problem is real. If the numbers you just put in look uncomfortable, that is usually worth a conversation.
Stay ahead of the integration layer.
Integronauts Signal — practical enterprise integration, API and agentic AI thinking. The tools stay free either way.
Integronauts Signal is launching soon.
Practical enterprise integration, APIs, agentic AI and emerging architecture. Sign-up opens when the list does — nothing to enter yet.

