tesserakit-gha
Lint GitHub Actions workflows for security and hygiene.
tessera-gha parses .github/workflows/*.yml, inventories jobs/steps/actions, and flags the workflow mistakes that lead to supply-chain and injection incidents. It reads YAML only; it never runs a workflow.
Lint
tessera gha lint --input . --output ./out/gha_pack
Point it at a repo root (it finds .github/workflows/), a workflows directory, or a single workflow file.
Artifacts written:
items.jsonl one WorkflowItem per step (uses/run, pin status, injection flag)
workflows.jsonl per-workflow facts (triggers, jobs, permissions/timeout gaps)
index.md workflow + action inventory
validation_report.md security + hygiene findings
coverage_report.md actions used, run vs uses counts
Findings
pull_request_target_checkout_rce(error) — a privileged trigger (pull_request_target/workflow_run) and a checkout of PR-controlled code (ref: ${{ github.event.pull_request.head.sha }}etc.); the classic CI remote-code-execution comboscript_injection_risk(error) — arun:script interpolates an untrustedgithub.event.*field (title/body/branch); use an intermediateenv:varunpinned_action(warning) — a third-party action isn't pinned to a commit SHA (tags are mutable)persist_credentials(warning) — a checkout keeps theGITHUB_TOKENon disk (persist-credentialsnot disabled)write_all_permissions(warning) —permissions: write-allor broadly-write scopesrisky_trigger(warning) —pull_request_target/workflow_runrun with secrets on untrusted inputmissing_permissions(info) — no explicitpermissions:; jobs get broad default scopesmissing_timeout(info) — a job has notimeout-minutesparse_error,no_workflows
Metadata
Release files for tesserakit-gha 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| tesserakit_gha-0.4.0.tar.gz | 7.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| tesserakit_gha-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.8 kB
Release files / tesserakit_gha-0.4.0.tar.gz
| Download URL | tesserakit_gha-0.4.0.tar.gz |
|---|---|
| Size | 7.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
183f8c286962651ce08715ad5c07b35367220c884d791ba357e4cdab19686a27
|
|
BLAKE2b-256 checksum How to use checksums |
7ef43c33c5740dbf66ae1488ab29922a790e72dd7ab8cb1267d84528d285fb37
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|
Release files / tesserakit_gha-0.4.0-py3-none-any.whl
| Download URL | tesserakit_gha-0.4.0-py3-none-any.whl |
|---|---|
| Size | 9.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c2747be44cf77663fe5d4d0be8bf3c66157b8c53fe9f62d18d85f7c160800470
|
|
BLAKE2b-256 checksum How to use checksums |
2d7efab2b06dcbc1fb8293db975af2b3d9d3f4b99cc2cb77a0f0c3267f243888
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.11
|