3 projects
gha-audit
Scan .github/workflows for known GitHub Actions supply-chain and CI security misconfigurations (unpinned actions, pwn requests, script injection, over-broad permissions).
weight-audit
License compliance scanner for open-weight AI models (Llama, Gemma, Qwen, DeepSeek, and more)
license-radar
Scan project dependency manifests for license compliance risk (GPL/AGPL/LGPL exposure) before it becomes a legal problem.