{"repo":"synacktiv/octoscan","free":true,"listed":false,"github":"https://github.com/synacktiv/octoscan","clone":"git clone https://github.com/synacktiv/octoscan.git","description":"Octoscan is a static vulnerability scanner for GitHub action workflows.","language":"Go","stars":272,"topics":["cicd","exploit","github","github-actions","vulnerability"],"license":"GPL-3.0","category":"security-tools","readme_excerpt":":octocat: octoscan Octoscan is a static vulnerability scanner for GitHub action workflows. Table of Contents - Table of Contents - Installation - Usage - download remote workflows - analyze - GitHub action - Rules - dangerous-checkout - dangerous-action - dangerous-write - expression-injection - runner-label - repo-jacking - unsecure-commands - bot-check - known-vulnerability - dangerous-artefact - credentials - shellcheck - local-action - oidc-action - Credits - Resources Installation Or with docker: Usage download remote workflows Octoscan can be run against a local git repository or you can download all the workflows with the dl action: analyze If you don't know what to run just run this: It will reduce false positives and give the most interesting results. If you have downloaded the workflows with the dl command you might have duplicated workflows since by default octoscan will download all the workflows of all the branches. To delete duplicated workflows and speed up the analysis you can use the fdupes command before running the analysis: GitHub action This tool can also be used directly as a GitHub action to scan your repository on push / pull request events. For more information please check this repository. Rules The complete list of rules can be found with this command: dangerous-checkout Triggers like workflow run or pull request target run in a privileged context, as they have read access to secrets and potentially have write access on the targeted repository. Perf","default_branch":null,"files":null,"tree":[],"storefront":"/r/synacktiv","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/synacktiv/octoscan/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}