{"repo":"boostsecurityio/poutine","free":true,"listed":false,"github":"https://github.com/boostsecurityio/poutine","clone":"git clone https://github.com/boostsecurityio/poutine.git","description":"poutine, a supply chain vulnerability scanner for build pipelines","language":"Go","stars":506,"topics":["ci","cli","devops","devsecops","github","github-actions","golang","security","security-scanner","supply-chain"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"poutine Created by BoostSecurity.io, poutine is a security scanner that detects misconfigurations and vulnerabilities in the build pipelines of a repository. It supports parsing CI workflows from GitHub Actions and Gitlab CI/CD. When given an access token with read-level access, poutine can analyze all the repositories of an organization to quickly gain insights into the security posture of the organization's software supply chain. See the documentation for a list of rules currently supported by poutine . Why poutine ? In French, the word \"poutine\", when not referring to the dish, can be used to mean \"messy\". Inspired by the complexity and intertwined dependencies of modern open-source projects, poutine reflects both a nod to our Montreal roots and the often messy, complex nature of securing software supply chains. Supported Platforms - GitHub Actions - Gitlab Pipelines - Azure DevOps - Pipelines As Code Tekton Getting Started Installation To install poutine , download the latest release from the releases page and add the binary to your $PATH. Homebrew Docker GitHub Actions Usage Analyze a local repository Analyze a remote GitHub repository Analyze all repositories in a GitHub organization Analyze all projects in a self-hosted Gitlab instance Configuration Options See .poutine.sample.yml for an example configuration file. Version check telemetry By default, poutine reaches out at most once every 24 hours to check whether a newer release is available. The request reports the c","default_branch":null,"files":null,"tree":[],"storefront":"/r/boostsecurityio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/boostsecurityio/poutine/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}