Developer Tools
Pipelineweft: CI Audit
Harden Workflow YAML
iOSfor iPhone and iPad
- $0.99 one-time purchase
- No account
- No ads or app telemetry
Screenshots
4 images · iPhone 6.7"
iPad
4 images · iPad Pro 12.9" (3rd gen)
About Pipelineweft: CI Audit
Pipelineweft is a private CI workflow security desk for developers, maintainers, consultants, and small platform teams reviewing the code path that builds, signs, publishes, and deploys their software.
Turn visible YAML risks into a line-level remediation register before privileged automation handles code, tokens, artifacts, or deployments.
KEY FEATURES
- Workflow YAML heuristic import
- Mutable action reference detection
- Broad permission and trigger screen
- Untrusted interpolation findings
- Per-job least-privilege notes
- Workflow-change ownership register
- Remediation artifact export
- Repository content stays local
- Native structured-file or CSV import
- Local PDF, workspace JSON, and domain-artifact export
- 48 original offline technical reference plates
- No account, ads, analytics, tracking, IAP, or subscription
Pipelineweft performs local text heuristics and records review decisions; it does not fetch action source, verify commit provenance, inspect repository settings, or certify a pipeline. Review platform documentation, organization policy, secrets, runners, environments, and called workflows with security owners.
A Shadowfetch app. Published on the App Store by Robert Corbin.