Pipelineweft icon
One-time iPhone and iPad app

Pipelineweft

Import workflow YAML offline, find mutable actions, broad token permissions, risky triggers, and untrusted interpolation, then export a remediation plan.

Focused field tools

Immutable Inputs

Pin third-party actions and images to verified immutable identifiers.

Permissions

Start from no token access and grant the minimum per job.

Untrusted Context

Keep pull request titles, branches, bodies, and comments out of executable scripts.

Triggers

Treat privileged pull-request targets and reusable workflow boundaries carefully.

Secrets

Prefer short-lived identity, mask output, and isolate untrusted work.

Runners

Separate persistent self-hosted infrastructure from hostile contributions.

Pipelineweft performs local text heuristics and records review decisions; it does not fetch action source, verify commit provenance, inspect repository settings, or certify a pipeline. Review platform documentation, organization policy, secrets, runners, environments, and called workflows with security owners.