chainsaw scan-actions
Scan GitHub Actions workflows for supply-chain risk
Scan GitHub Actions workflows for supply-chain risk
chainsaw scan-actions <path>
Scan one or more GitHub Actions workflow YAML files for supply-chain issues — unpinned refs, typosquats, unknown publishers, and known-malicious actions.
<path> may be either a directory (the command walks <path>/.github/workflows/) or a single workflow YAML file.
Output formats (–format, a global flag): text (the default), json, sarif. –json is sugar for –format=json. Every format honours –output.
Exit codes:
0 — no high-severity findings (low/medium are still reported)
1 — at least one high-severity finding (suitable for set -e CI gates)