PipelineGuard
Local-first · live intelligence optional

DEVSECOPS SECURITY PREFLIGHT

Catch pipeline risks before production.

Drop an entire repository ZIP or individual security-relevant files. PipelineGuard inventories the project, scans exposed secrets, pipelines, containers, IaC, and dependencies, then correlates risks across files. Repository extraction stays local.

Repository ZIPCI/CDSecretsDockerKubernetesTerraformSupply ChainLive CVEs

FIRST 60 SECONDS

See PipelineGuard work before you configure anything.

Run a focused risky-repository demo, inspect a compound CI/credential finding, suppress one with an auditable exception, then export the report. No upload or relay is needed for the demo.

1Run demo~10 sec
2Review risk~30 sec
3Suppress / export~60 sec
/100

2 · SECURITY POSTURE

Ready to scan

Add one or more files to generate a local DevSecOps preflight assessment.

0Critical
0High
0Medium
0Low
1
InputFiles / repository
2
SecretsCredential patterns
3
CI/CDWorkflow security
4
ContainersDocker + Kubernetes
5
IaCTerraform exposure
6
Supply chainDependency hygiene
7
CorrelateCross-file risks
8
ReportProject posture

LIVE INTELLIGENCE · OPTIONAL

Known-vulnerability lookup

Not checked

After a local scan, PipelineGuard can send only exact package coordinates (ecosystem, package name, version) to your relay for OSV advisory matching. Source files and secrets are not sent.

0Exact versions found
0Known advisories
0Critical/high
0Fix version noted
Relay configuration
Frontend 0.6.1 · Relay not tested
The relay URL is stored only in this browser's localStorage. Health tests do not send repository content.

3 · FINDINGS

Prioritized remediation

No scan results yet

Your files stay on this device. Add files and run a scan to see prioritized findings.

ZIP

Whole-repository audit

Unpacks repository ZIPs locally, skips generated/vendor content, inventories security-relevant files, and scans source code for secrets.

Secrets detection

Flags common credential formats and suspicious hardcoded secret assignments while redacting evidence.

Workflow hardening

Checks action pinning, token permissions, dangerous triggers, shell patterns, and untrusted interpolation.

Docker checks

Reviews image tags, root execution, build-time secrets, remote ADD instructions, and risky shell installs.

Kubernetes posture

Finds privileged workloads, host access, root execution, weak security contexts, risky mounts, and token exposure.

Terraform / IaC

Reviews public ingress, public databases, storage access controls, wildcard IAM, encryption, and cloud metadata settings.

Dependency hygiene

Reviews npm, Python, NuGet, Maven, and Gradle manifests for dynamic versions, insecure sources, install hooks, reproducibility gaps, and optional live advisories.

Cross-file correlation

Combines related findings across CI, containers, cloud infrastructure, credentials, and package installation to surface compound repository risks.

Auditable suppressions

Suppress false positives with a required justification and expiration date. Exceptions persist locally, expire automatically, and remain visible in reports.

Actionable report

Produces deterministic scoring, line-level evidence, suggested fixes, and a standalone HTML report.

SCOPE

Static preflight, not a penetration test

PipelineGuard v0.6.1 uses local repository extraction, pattern analysis, configuration rules, and cross-file correlation. It does not execute uploaded code or prove that a detected credential is valid. Optional live advisory checks query OSV through the configured relay. Review findings before changing production systems.

SYSTEM STATUS

Runtime & deployment diagnostics

These checks help distinguish a browser limitation, frontend/relay version mismatch, or upstream advisory outage. Repository contents are not sent by this screen.

Frontend0.6.1Ready
Repository ZIPChecking…
Persistent storageChecking…
ClipboardChecking…
Report downloadChecking…
Live networkingChecking…
RelayNot tested
OSV upstreamNot tested

HOW IT WORKS

Local static analysis

  1. Add individual files or a repository ZIP. ZIP contents are unpacked and filtered locally in the browser.
  2. PipelineGuard reads the text with JavaScript in your browser.
  3. Rules evaluate secrets, CI/CD controls, containers, cloud IaC, dependency manifests, package sources, install hooks, and compound cross-file risks.
  4. Findings are scored by severity and displayed with remediation guidance.

Privacy: v0.6.1 keeps local scanning local; live advisory checks send only package names, ecosystems, and versions to your configured relay. Your scan input is not intentionally transmitted by PipelineGuard.

FALSE-POSITIVE MANAGEMENT

Suppress this finding

When the expiration date passes, this finding automatically returns to the active results and score. Suppressions are stored only in this browser.

EXCEPTION REGISTER

Finding suppressions

Active suppressions are excluded from the score until their expiration date. Expired records remain visible here until removed.