Skip to main content

cicheck

CI PyPI

A security linter for the CI platforms that don't have one.

GitHub Actions has zizmor. Everyone else, GitLab CI, CircleCI, Azure Pipelines, Bitbucket, Drone and Travis, has the same classes of bug and no equivalent tool. cicheck reads those pipeline files and flags the common ones: hard-coded secrets, unpinned images, shell injection through branch names and commit messages, curl | bash, and a Docker socket mounted into the job.

Runs offline. No API calls, nothing leaves your machine.

cicheck flagging shell injection, an unpinned image and a mounted docker socket

Install

pip install cicheck

Usage

cicheck                  scan the current directory
cicheck path             scan a directory or a single CI file
cicheck --min high       only high and critical findings
cicheck --json           machine-readable output

Exit status is 0 when clean, 1 when there is a finding at or above the fail level (--fail-on, default high), and 2 on error.

pre-commit

repos:
  - repo: https://github.com/ReazGan/cicheck
    rev: v0.1.0
    hooks:
      - id: cicheck

GitHub Action

- uses: actions/checkout@v4
- uses: ReazGan/cicheck@v0.1.0
  with:
    fail-on: high

What it checks

Check Severity What it finds
hardcoded-secret critical A real-looking credential written into the pipeline file.
shell-injection high A branch name, commit message or MR/PR title interpolated into a shell command.
docker-socket high /var/run/docker.sock mounted into a job (root on the runner).
unpinned-image medium A container image with no fixed tag, or :latest.
curl-pipe-shell medium A downloaded script piped straight into a shell.

Covers .gitlab-ci.yml (and .gitlab/**), .circleci/config.yml, azure-pipelines.yml, bitbucket-pipelines.yml, .drone.yml and .travis.yml. Injection and curl | bash are only checked inside actual script blocks, so rules:/if: conditions and variable definitions don't cause noise.

License

MIT

Metadata

Release files for cicheck 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cicheck 0.1.0
File Size Uploaded
cicheck-0.1.0.tar.gz 12.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cicheck 0.1.0
File Interpreter ABI Platform
cicheck-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 24.1 kB

Release files / cicheck-0.1.0.tar.gz

Download URL cicheck-0.1.0.tar.gz
Size 12.5 kB
Tags Source
SHA-256 checksum
How to use checksums
5be4bd8bc598b27ae83f0db9901387203cac229a4f7df067aa83d5ecb97e9417
BLAKE2b-256 checksum
How to use checksums
825b6d4aed7b6c88f73ddc2cb53888d05fe1b444ded5178eea5b00af041b756d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release files / cicheck-0.1.0-py3-none-any.whl

Download URL cicheck-0.1.0-py3-none-any.whl
Size 11.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
80643ab06259c1c012b4f6b6bc449f767cacce0df4cc8782c367efc27b097515
BLAKE2b-256 checksum
How to use checksums
48271d9d4b77642f4f6e2544f2bd6b66a2c051ff133ad588ab4a4a2b5057cfb6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 5, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page