Whole-repository audit
Unpacks repository ZIPs locally, skips generated/vendor content, inventories security-relevant files, and scans source code for secrets.
DEVSECOPS SECURITY PREFLIGHT
Drop an entire repository ZIP or individual security-relevant files. PipelineGuard inventories the project, scans exposed secrets, pipelines, containers, IaC, and dependencies, then correlates risks across files. Repository extraction stays local.
FIRST 60 SECONDS
Run a focused risky-repository demo, inspect a compound CI/credential finding, suppress one with an auditable exception, then export the report. No upload or relay is needed for the demo.
2 · SECURITY POSTURE
Add one or more files to generate a local DevSecOps preflight assessment.
LIVE INTELLIGENCE · OPTIONAL
After a local scan, PipelineGuard can send only exact package coordinates (ecosystem, package name, version) to your relay for OSV advisory matching. Source files and secrets are not sent.
3 · FINDINGS
Your files stay on this device. Add files and run a scan to see prioritized findings.
Unpacks repository ZIPs locally, skips generated/vendor content, inventories security-relevant files, and scans source code for secrets.
Flags common credential formats and suspicious hardcoded secret assignments while redacting evidence.
Checks action pinning, token permissions, dangerous triggers, shell patterns, and untrusted interpolation.
Reviews image tags, root execution, build-time secrets, remote ADD instructions, and risky shell installs.
Finds privileged workloads, host access, root execution, weak security contexts, risky mounts, and token exposure.
Reviews public ingress, public databases, storage access controls, wildcard IAM, encryption, and cloud metadata settings.
Reviews npm, Python, NuGet, Maven, and Gradle manifests for dynamic versions, insecure sources, install hooks, reproducibility gaps, and optional live advisories.
Combines related findings across CI, containers, cloud infrastructure, credentials, and package installation to surface compound repository risks.
Suppress false positives with a required justification and expiration date. Exceptions persist locally, expire automatically, and remain visible in reports.
Produces deterministic scoring, line-level evidence, suggested fixes, and a standalone HTML report.
SCOPE
PipelineGuard v0.6.1 uses local repository extraction, pattern analysis, configuration rules, and cross-file correlation. It does not execute uploaded code or prove that a detected credential is valid. Optional live advisory checks query OSV through the configured relay. Review findings before changing production systems.