{"repo":"harekrishnarai/flowlyt","free":true,"listed":false,"github":"https://github.com/harekrishnarai/flowlyt","clone":"git clone https://github.com/harekrishnarai/flowlyt.git","description":"Flowlyt is a security analyzer that scans GitHub Actions workflows to detect malicious patterns, misconfigurations, and secrets exposure, helping enforce secure CI/CD practices.","language":"Go","stars":17,"topics":["ci-cd","github-actions","hacktoberfest","security","flowlyt"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Flowlyt A static security analyzer for GitHub Actions and GitLab CI/CD workflows. Presented at AppSec Village DEF CON 33 and Black Hat Europe 2025. Installation Homebrew (macOS / Linux) Go Or build from source: Usage Scan a local repository Scan a single workflow file Scan a remote repository Scan a specific ref (branch, tag, or commit SHA) --branch is kept as an alias of --ref for backward compatibility. Both the scanned content and the file links in the report use the given ref. Output formats How It Works Flowlyt parses workflow files into an AST, runs a rule engine across the tree (injection, secrets, supply chain, misconfigurations), then optionally passes findings through an AI layer for false positive verification. Results are emitted as text, JSON, or SARIF. Features - 110+ security rules covering injection, secrets, supply chain, and misconfigurations - AST-based analysis with call graph, reachability, and data flow - AI-assisted false positive reduction (OpenAI, Gemini, Claude, Grok, Perplexity) - Context-aware severity adjustment based on workflow type and triggers - Dependabot configuration auditing ( .github/dependabot.yml ) - SARIF output for GitHub Security tab integration - OSV.dev vulnerability intelligence - Custom rules and policy enforcement - GitHub Actions and GitLab CI/CD support GitHub Actions Integration AI analysis is available via CLI only. Use --ai flag for AI-enhanced local scans. AI Analysis Flowlyt supports AI-assisted verification using your ow","default_branch":null,"files":null,"tree":[],"storefront":"/r/harekrishnarai","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/harekrishnarai/flowlyt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}