Developer Tools

Pipelineweft: CI Audit

Harden Workflow YAML

iOSfor iPhone and iPad

  • $2.99 one-time purchase
  • No account
  • No ads or app telemetry

View on the App Store

About Pipelineweft: CI Audit

Pipelineweft audits GitHub Actions workflow YAML for supply-chain risk — a scored security review of your CI pipeline that runs entirely on your device.

The workbench puts your workflow source and its audit report on one screen: side by side on iPad and other wide displays, one flip apart on iPhone. Edit the YAML in a monospaced editor, tap Run Audit, and the supply-chain posture report updates with a 0–100 score, a findings-by-severity chart, and every finding pinned to its line number with a concrete remediation.

WHAT IT CHECKS
• Actions pinned to tags instead of reviewed 40-character commit SHAs
• Secrets interpolated directly into run: shell text
• Privileged pull_request_target triggers
• write-all token permissions
• Self-hosted runners receiving workflow code
• Missing explicit permissions block (implicit token scope)

FEATURES
• Monospaced YAML editor with autocorrection disabled
• Severity-weighted score — criticals cost more than warnings
• Findings sorted critical-first, each with line number and fix
• Findings-by-severity bar chart
• Executable step count (uses: and run:) at a glance
• Sample workflow included so you can explore every check immediately

PREMIUM BY DESIGN
One-time paid download. No account, no ads, no analytics, no tracking, and no network access at all — your workflow YAML never leaves the device. Works completely offline.

A Shadowfetch app. Published on the App Store by Robert Corbin.