GitHub Actions Security Linter

Check workflows for the security and reliability mistakes attackers exploit — with a concrete fix for each finding.

Loading Tool...

Help shape GitHub Actions Security Linter

The bug you just noticed will fade in 3 minutes. The feature idea will vanish after your next tab switch. Crazy peps don't suffer silently.

0/1000

Frequently Asked Questions

Expressions like ${{ github.event.issue.title }} are pasted into the shell before it runs, so a crafted title can execute commands. Pass the value through env: and quote the variable instead.

Tags like v1 can be moved to point at different code. A full 40-character SHA can't change, which protects you if an action is compromised.

A pull_request_target or workflow_run workflow that checks out and runs code from an untrusted pull request while holding write tokens and secrets.

No. Everything is checked locally in your browser.