Pipelineweft
Import workflow YAML offline, find mutable actions, broad token permissions, risky triggers, and untrusted interpolation, then export a remediation plan.
Focused field tools
Pin third-party actions and images to verified immutable identifiers.
Start from no token access and grant the minimum per job.
Keep pull request titles, branches, bodies, and comments out of executable scripts.
Treat privileged pull-request targets and reusable workflow boundaries carefully.
Prefer short-lived identity, mask output, and isolate untrusted work.
Separate persistent self-hosted infrastructure from hostile contributions.
Pipelineweft performs local text heuristics and records review decisions; it does not fetch action source, verify commit provenance, inspect repository settings, or certify a pipeline. Review platform documentation, organization policy, secrets, runners, environments, and called workflows with security owners.