General
CI Pipeline & Container Build Security Scanner
github-actions-audit scans GitHub Actions workflows for supply-chain risks, while dockerfile-audit audits the Dockerfiles those workflows build — creating a paired security review of the full CI-to-image pipeline. The correlates findings to identify cases where a compromised workflow could push a vulnerable image.
Tools connected
- GitHub
- Hadolint
- Apify
What it automates
correlation → dockerfile-audit.image_findings
Want this one built?
Schedule it and we'll build it in the next 24 hours — you'll get an email the moment it goes live.