chainsaw scan-actions

Scan GitHub Actions workflows for supply-chain risk

Scan GitHub Actions workflows for supply-chain risk

chainsaw scan-actions <path>

Scan one or more GitHub Actions workflow YAML files for supply-chain issues — unpinned refs, typosquats, unknown publishers, and known-malicious actions.

<path> may be either a directory (the command walks <path>/.github/workflows/) or a single workflow YAML file.

Output formats (–format, a global flag): text (the default), json, sarif. –json is sugar for –format=json. Every format honours –output.

Exit codes: 0 — no high-severity findings (low/medium are still reported) 1 — at least one high-severity finding (suitable for set -e CI gates)