{"repo":"koki-develop/ghasec","free":true,"listed":false,"github":"https://github.com/koki-develop/ghasec","clone":"git clone https://github.com/koki-develop/ghasec.git","description":"🫴 Catch security risks in your GitHub Actions workflows.","language":"Go","stars":52,"topics":["github-actions","security"],"license":"MIT","category":"security-tools","readme_excerpt":"ghasec Catch security risks in your GitHub Actions workflows. Installation Homebrew Go Docker GitHub Releases Download the binary for your platform from the Releases page. GitHub Actions - ghasec-action - A GitHub Action to run ghasec. - setup-ghasec - A GitHub Action to install ghasec. Use this if you want to run ghasec with custom options. Usage When run without arguments, ghasec automatically discovers .github/workflows/ .yml yaml and /action.yml yaml files in the current directory. You can also specify files explicitly: Online Rules Some rules require network access to the GitHub API. Use the --online flag to enable them: The GitHub API is subject to rate limiting. Set the GHASEC GITHUB TOKEN or GITHUB TOKEN environment variable to use a higher rate limit: Markdown Format Use --format markdown to produce Markdown output. Each diagnostic includes the source line, a description of why the issue matters, and how to fix it: This format is useful for AI agents like Claude Code or Cursor — pass the output directly and let the agent fix the issues autonomously. SARIF Format Use --format sarif to produce SARIF 2.1.0 output. This enables integration with reviewdog, GitHub Code Scanning, and other SARIF-consuming tools. Ignoring Rules Add a # ghasec-ignore: comment above the line to suppress a specific diagnostic: Multiple rules can be separated by commas: Omit the rule name to suppress all diagnostics on the line: Rules See Rules for the full list of available rules. License MIT","default_branch":null,"files":null,"tree":[],"storefront":"/r/koki-develop","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/koki-develop/ghasec/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}