Kumar Ashwin

[email protected]
Projects
SecurityCI/CDSupply ChainGitHub

actsense - Workflow Security Auditor

See every dependency your CI workflows actually run, and fix what it exposes

actsense is an open-source workflow security auditor. It maps every dependency your CI workflows actually run (actions, reusable workflows, container images and packages), audits each one at the exact version it runs, and turns findings into line-level fixes. It catches pwn requests, script injection, environment poisoning, runner takeover, leaked credentials and mutable dependencies. GitHub Actions is fully supported today, and it runs self-hosted in a single container.