Workflow Security Auditor. Maps every dependency your CI workflows run, at the version they run, and audits each one. GitHub Actions is supported today; the architecture is built so other workflow platforms can follow.
🙌 Refer to https://actsense.dev for the guide 📖
- 🔍 Comprehensive Security Auditing: Detects ~70 security issues and exposures in GitHub Actions workflows
- 📊 Interactive Graph Visualization: Visualize action dependencies with an interactive graph
- 🔎 Powerful Search: Search security issues and assets with natural language queries (Cmd+K / Ctrl+K)
- 📋 Table Views: View nodes and dependencies in organized table formats
- 🔗 Transitive Dependency Analysis: Automatically resolves and audits all action dependencies
- 💾 Analysis History: Save and load previous analyses
- 🔐 Multiple Analysis Methods: Use GitHub API, clone repositories locally, or analyze YAML directly
- ✏️ YAML Editor: Paste and analyze workflow YAML directly with real-time validation
- 📖 Detailed Issue Documentation: Each vulnerability links to comprehensive documentation on actsense.dev
- 🎨 Modern UI: Clean, professional interface built with React
For detailed installation instructions including Docker, quick setup, and manual installation options, see the Getting Started guide.
For a comprehensive guide on using actsense, including interactive features, search functionality, and detailed analysis capabilities, see the Usage documentation.
A GitHub Personal Access Token increases rate limits from 60/hour to 5,000/hour.
Create a token with public_repo scope (or repo for private repos).
actsense detects issues including:
- Unpinned action versions
- Older action versions (checks against latest from GitHub)
- Inconsistent action versions across workflows
- Hardcoded secrets
- Overly permissive permissions
- Unpinnable actions (Docker, composite, JavaScript)
- Script injection vulnerabilities
- Untrusted third-party actions
- And 30+ more security issues
By default, actsense flags actions from unknown publishers when secrets are passed to them. You can configure which publishers are trusted by editing backend/config.yaml.
To add a trusted publisher:
- Open
backend/config.yaml - Add the publisher prefix to the
trusted_publisherslist:
trusted_publishers:
- "actions/"
- "github/"
# ... existing publishers ...
- "your-org/"- Restart the application
Example: To trust 0xCardinal/Publish-Docker-Github-Action@v5, add "0xCardinal/" to the list. This will trust all actions from the 0xCardinal organization.
Each security issue detected by actsense includes:
- Title and Description: Clear explanation of the vulnerability
- Evidence: Specific details about where and how the issue was found
- Mitigation Strategy: Step-by-step guidance on how to fix the issue
- External Reference: Links to comprehensive documentation on actsense.dev
All vulnerability documentation is available at docs/content/vulnerabilities/ and hosted on actsense.dev.
See CONTRIBUTING.md for technical details, API documentation, and development guidelines.
Thank you to all contributors who help make actsense better!
0xCardinal |
Made with ❤️ by the actsense team