Open-source Workflow Security Auditor

actsense

See every dependency your CI workflows actually run, at the exact version they run, and what each one exposes. Then fix it.

Works with GitHub Actions
Quickstart docker run --rm -p 8000:8000 ghcr.io/0xcardinal/actsense:latest
  • Comprehensivedocumented checks, each with a fix
  • Every layercomposite actions, reusable workflows, images
  • Pinned refsaudited at the version that runs, not main
  • 1 containerself-hosted; your workflows stay with you

The attacks it catches

The patterns behind real CI/CD compromises, found in your workflows and in every dependency they pull in. Shown here for GitHub Actions.

How it works

  1. 1

    Point it at a repository

    An owner/repo, a single owner/repo@ref action, or a workflow file you paste in.

  2. 2

    It maps the whole supply chain

    Workflows, local and remote actions, nested reusable workflows, Docker base images and installed packages, each fetched at the ref your workflow pins.

  3. 3

    Every node is audited

    Findings land on the exact node and line, ranked by severity, each linked to a page explaining the risk and the fix.

Fix, not just flag

The workflow editor turns findings into line-level fixes you can apply in one click. Tags are resolved to commit SHAs and image digests through pin., so pinning works without a GitHub token.

-      - uses: actions/checkout@v4
+      - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
-    container: nginx:1.27
+    container: nginx@sha256:6784fb08…c05f7d # 1.27

Supported platforms

actsense is a workflow security auditor. GitHub Actions is fully supported today; the engine is built so other workflow platforms can be added.

Available now

Supported

GitHub Actions

Workflows, composite and JavaScript actions, reusable workflows, Docker actions and job containers.

Get started →

Planned — tell us which one you need

GitLab CI/CD

Planned

Jenkins

Planned

AWS CodePipeline

Planned

Tekton

Planned

Argo Workflows

Planned

What's covered

Audit your first repository in a minute