ghalint
Command-line linter that checks GitHub Actions workflows against security best practices.
Desktopfreeglobal

ghalint is a command-line linter that checks GitHub Actions workflow files against security best practices — flagging overly broad permissions, unpinned action references, and secrets set as environment variables, among other policies. It's for engineering and security teams who want to catch CI/CD misconfigurations automatically instead of reviewing every workflow file by hand.
Categories
security toolsdeveloper toolsCI/CD tools
Something wrong with this listing — dead link, not a real product, wrong info?

