CI/CD Pipeline Security Scanner + Multi-format Config Converter
pipeguard is a fast Rust CLI for security engineers and builders who care about their pipelines.
It does two things extremely well:
- Scans GitHub Actions, GitLab CI, Dockerfiles,
.env, and other pipeline files for real security issues - Converts cleanly between YAML ↔ JSON ↔ TOML
Built for practical use during code review, recon, and hardening your own CI.
Misconfigured CI/CD is one of the highest-ROI attack surfaces. Most teams still pin actions to tags, over-permission jobs, and leak secrets into logs. pipeguard finds these problems offline, fast, and with SARIF output ready for GitHub Code Scanning.
| Rule ID | Severity | Description |
|---|---|---|
unpinned-action |
High | Actions pinned to tags/branches instead of SHAs |
permissions-write-all |
High | permissions: write-all |
excessive-write-permissions |
Medium | Too many individual write scopes |
dangerous-permission-combo |
High | contents: write + id-token: write |
pull-request-target |
Critical | Dangerous pull_request_target trigger |
pr-target-untrusted-checkout |
Critical | pull_request_target + checkout of PR head |
persist-credentials |
Medium | Checkout leaves GITHUB_TOKEN in workspace |
env-hardcoded-secret |
High | Literal secrets assigned in env: |
self-hosted-runner |
Medium | Use of self-hosted runners |
secret-in-logs |
High | Secrets being echoed |
script-injection |
High | Untrusted github.event data used in run: |
curl-pipe-shell |
High | curl | bash / wget | sh |
image-latest |
Medium | Image or FROM tagged :latest |
privileged-container |
High | Privileged container |
insecure-ssl |
High | TLS verification disabled |
world-writable |
Medium | chmod 777 |
aws-access-key / github-pat / stripe-key / openai-key |
Critical | Known secret patterns |
high-entropy-secret |
Medium | High Shannon entropy string |
- Human-readable (colored)
- JSON
- SARIF (GitHub Code Scanning ready)
Create a .pipeguardignore next to the scan root:
# rule IDs
self-hosted-runner
# path fragments
examples/
Or suppress one line with # pipeguard-ignore.
- uses: actions/checkout@v4
- uses: Steeve-Crypto/pipeguard@v0.1.0
with:
path: .github/workflows
min_severity: medium
exclude: self-hosted-runner
sarif: pipeguard.sarif
fail_on_findings: "true"
comment_pr: "true"
- uses: github/codeql-action/upload-sarif@v4
if: always()
with:
sarif_file: pipeguard.sarifThe Action builds from the tag you pin, so @v0.1.0 and later checkouts stay consistent.
cargo install pipeguardpipeguard scan .github/workflows/
pipeguard scan . --min-severity high --fail-on high
pipeguard scan . --exclude self-hosted-runner,image-latest
pipeguard scan . --json
pipeguard scan . --sarif > results.sarif
pipeguard rules
pipeguard convert config.yaml --to jsonInstrumented with tracing. Structured events for every finding, scan metrics, and JSON logs for collectors.
Live scan of an intentional insecure workflow fixture (docs/demo/demo.yml):
pipeguard scan docs/demo/demo.ymlFindings shown: pull_request_target, permissions: write-all, unpinned action, curl | bash, secret echo.
MIT
