vamp-ci-audit
CI/CD pipeline security auditor — GitHub Actions, GitLab CI and Forgejo Actions
© VampSecure Studios — VampSecure Labs Security Research Division
Para Uso Exclusivo en Pruebas de Penetración Autorizadas
Instalación
pip install vamp-ci-audit
Uso
# Escanear directorio actual (busca workflows automáticamente)
vamp-ci-audit scan .
# Escanear workflows de GitHub Actions
vamp-ci-audit scan .github/workflows/
# Escanear un fichero concreto
vamp-ci-audit scan workflow.yml
# Salida JSON
vamp-ci-audit scan . --format json
# Informe HTML
vamp-ci-audit scan . --output informe.html
# Solo hallazgos HIGH y CRITICAL
vamp-ci-audit scan . --severity HIGH
Checks incluidos
| ID | Severidad | Descripción |
|---|---|---|
| CI-001 | CRITICAL | Secret hardcodeado en bloque env: |
| CI-002 | HIGH | pull_request_target con checkout de código del PR |
| CI-003 | HIGH | Expression injection — variable controlable en run: |
| CI-004 | HIGH | Action externa sin SHA pin (ref mutable) |
| CI-005 | HIGH | Permisos write-all o write en scopes sensibles |
| CI-006 | MEDIUM | Self-hosted runner sin label de restricción |
| CI-007 | MEDIUM | Ruta de artefacto con expresión controlable por atacante |
| CI-008 | MEDIUM | Cache key con rama/PR controlable (cache poisoning) |
| CI-009 | MEDIUM | Input workflow_dispatch sin validación en run: |
| CI-010 | LOW | GITHUB_TOKEN con write innecesario en job de build/test |
Plataformas soportadas
- GitHub Actions (
.github/workflows/*.yml) - GitLab CI (
.gitlab-ci.yml) - Forgejo Actions (
.forgejo/workflows/*.yml)
Exit codes
0— Sin hallazgos1— Hallazgos encontrados2— Error de ejecución
Licencia
AGPL-3.0-only — Ver LICENSE
Metadata
Release files for vamp-ci-audit 1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vamp_ci_audit-1.0.tar.gz | 15.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vamp_ci_audit-1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 31.1 kB
Release files / vamp_ci_audit-1.0.tar.gz
| Download URL | vamp_ci_audit-1.0.tar.gz |
|---|---|
| Size | 15.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
63dbcb852459e9c363cca761e8a5ed47e11a5b9c3267ebce909c9b40513b3628
|
|
BLAKE2b-256 checksum How to use checksums |
f91787c3f2da105a3e74daa9e169d870e43fee3c8fcc70b73fc29aba7382ac6b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / vamp_ci_audit-1.0-py3-none-any.whl
| Download URL | vamp_ci_audit-1.0-py3-none-any.whl |
|---|---|
| Size | 15.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7e32650cc41644ad2237a767e07a1e80424837bd9b8a89e97cf68680d95353f9
|
|
BLAKE2b-256 checksum How to use checksums |
c4899cde3720ef6009f50895ac9ab03ec1f0430e5c2977efd4e2ea84b85a2a16
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|