Skip to content

Add gha-shield to Tools#26

Open
Fabridev444 wants to merge 1 commit into
myugan:mainfrom
Fabridev444:add-gha-shield
Open

Add gha-shield to Tools#26
Fabridev444 wants to merge 1 commit into
myugan:mainfrom
Fabridev444:add-gha-shield

Conversation

@Fabridev444
Copy link
Copy Markdown

Adds gha-shield to the Tools section.

What it is: browser + CLI + GitHub Action workflow security scanner. 13 categorized rules covering unpinned actions, command injection via interpolation, hard-coded provider keys, missing permissions, untrusted action receiving secrets, and 8 more. SARIF output integrates with the GitHub Security tab.

Differentiation vs the existing tools in the section:

  • Unlike actionlint (lint correctness), it focuses on security findings.
  • Unlike zizmor (CLI-only Rust), it ships browser-first (paste YAML, no install) AND as a Node CLI AND as an Action.
  • Unlike poutine (binary install), it runs zero-install via npx Fabridev444/gha-shield.

Receipts:

License: MIT-pending.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant