typofix
1 file changed
tree: e1e6d9557512a5988f46a7684323ee2f9e3a4113
  1. gha_scanner/
  2. tests/
  3. .gitignore
  4. gha_scanner.config
  5. Pipfile
  6. Pipfile.lock
  7. README.md
  8. scanner.py
README.md

ASF GitHub Actions Workflow Scanner

Setting up

pipenv install

Create a Read-Only GitHub token

Enter your GitHub token into the gha_scanner.config file. Optionally, copy the gha_scanner.config file somewhere else and pass it to scanner.py with -c/--config.

Starting

pipenv run python3 ./scanner.py

Logging

The policy scanner logs to logs/gha_scanner.log by default.