Skip to main content

tesserakit-gha

Lint GitHub Actions workflows for security and hygiene.

tessera-gha parses .github/workflows/*.yml, inventories jobs/steps/actions, and flags the workflow mistakes that lead to supply-chain and injection incidents. It reads YAML only; it never runs a workflow.

Lint

tessera gha lint --input . --output ./out/gha_pack

Point it at a repo root (it finds .github/workflows/), a workflows directory, or a single workflow file.

Artifacts written:

items.jsonl              one WorkflowItem per step (uses/run, pin status, injection flag)
workflows.jsonl          per-workflow facts (triggers, jobs, permissions/timeout gaps)
index.md                 workflow + action inventory
validation_report.md     security + hygiene findings
coverage_report.md       actions used, run vs uses counts

Findings

  • pull_request_target_checkout_rce (error) — a privileged trigger (pull_request_target/workflow_run) and a checkout of PR-controlled code (ref: ${{ github.event.pull_request.head.sha }} etc.); the classic CI remote-code-execution combo
  • script_injection_risk (error) — a run: script interpolates an untrusted github.event.* field (title/body/branch); use an intermediate env: var
  • unpinned_action (warning) — a third-party action isn't pinned to a commit SHA (tags are mutable)
  • persist_credentials (warning) — a checkout keeps the GITHUB_TOKEN on disk (persist-credentials not disabled)
  • write_all_permissions (warning) — permissions: write-all or broadly-write scopes
  • risky_trigger (warning) — pull_request_target / workflow_run run with secrets on untrusted input
  • missing_permissions (info) — no explicit permissions:; jobs get broad default scopes
  • missing_timeout (info) — a job has no timeout-minutes
  • parse_error, no_workflows

Metadata

Release files for tesserakit-gha 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for tesserakit-gha 0.4.0
File Size Uploaded
tesserakit_gha-0.4.0.tar.gz 7.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for tesserakit-gha 0.4.0
File Interpreter ABI Platform
tesserakit_gha-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 16.8 kB

Release files / tesserakit_gha-0.4.0.tar.gz

Download URL tesserakit_gha-0.4.0.tar.gz
Size 7.4 kB
Tags Source
SHA-256 checksum
How to use checksums
183f8c286962651ce08715ad5c07b35367220c884d791ba357e4cdab19686a27
BLAKE2b-256 checksum
How to use checksums
7ef43c33c5740dbf66ae1488ab29922a790e72dd7ab8cb1267d84528d285fb37
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release files / tesserakit_gha-0.4.0-py3-none-any.whl

Download URL tesserakit_gha-0.4.0-py3-none-any.whl
Size 9.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c2747be44cf77663fe5d4d0be8bf3c66157b8c53fe9f62d18d85f7c160800470
BLAKE2b-256 checksum
How to use checksums
2d7efab2b06dcbc1fb8293db975af2b3d9d3f4b99cc2cb77a0f0c3267f243888
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.11

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page