{"repo":"sisaku-security/sisakulint","free":true,"listed":false,"github":"https://github.com/sisaku-security/sisakulint","clone":"git clone https://github.com/sisaku-security/sisakulint.git","description":"CI-Friendly static linter with autofix, SAST, semantic analysis for GitHub Actions","language":"Go","stars":47,"topics":["autofix","github-actions","go","static-analysis","supply-chain-security"],"license":"Apache-2.0","category":"dev-tools","readme_excerpt":"sisakulint A fast, security-first static analyzer with heuristic auto-fix for GitHub Actions workflows. Find injection, credential leakage, supply-chain, and pipeline-poisoning bugs in .github/workflows/ — and let -fix repair most of them for you. --- Why sisakulint - Security-first by design. Full coverage of the OWASP Top 10 CI/CD Security Risks — code/env/path/output injection, untrusted checkouts, artifact & cache poisoning, ref confusion, impostor commits, and more. - Semantic, not regex. A real AST + expression parser + shell taint analyzer ( mvdan.cc/sh ) — not string matching. Cross-step and cross-file taint propagation through $GITHUB ENV , reusable workflow boundaries, and shell function arguments. - Auto-fix that ships PRs. 27+ rules carry an auto-fixer. sisakulint -fix on rewrites the YAML in place; -fix dry-run previews the diff first. - Built for CI. SARIF output drops straight into reviewdog for inline PR review comments. - AI-agent aware. Detects prompt injection, dangerous tool exposure, unsafe sandbox flags, and execution-order issues in claude-code-action and similar AI agent integrations (the Clinejection attack class). How it compares sisakulint actionlint zizmor StepSecurity CodeQL ---------------------------------------------- :---------: :--------: :-----: :------------: :-----: Workflow syntax / shell linting ✅ ✅ partial — — OWASP CI/CD Top-10 coverage full — partial runtime only partial Cross-file taint for reusable workflows ✅ — — — ✅ Cross-step / c","default_branch":null,"files":null,"tree":[],"storefront":"/r/sisaku-security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sisaku-security/sisakulint/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}