Skip to content

Add ci-doctor (CI cost+security audit) and pin-actions#780

Open
depmedicdev-byte wants to merge 1 commit intosdras:mainfrom
depmedicdev-byte:add-ci-doctor-and-pin-actions
Open

Add ci-doctor (CI cost+security audit) and pin-actions#780
depmedicdev-byte wants to merge 1 commit intosdras:mainfrom
depmedicdev-byte:add-ci-doctor-and-pin-actions

Conversation

@depmedicdev-byte
Copy link
Copy Markdown

What this adds

  • ci-doctor - Audit a workflow for cost waste, security gaps, and reliability issues. 16 rules, SARIF + PR comment via ci-doctor-action.

  • pin-actions - One-shot CLI that pins every uses: reference in your workflows to a SHA.

Why

depmedic ships a family of CI cost+security auditors covering GitHub, GitLab, Bitbucket, Azure Pipelines, and CircleCI. Each is a single-binary npx invocation, MIT, no telemetry, with SARIF + PR comment integration. They are well-tested (3-5 node --test suites each), versioned, and actively maintained.

Conformance

  • One line per entry in alphabetical order within the section
  • Description starts with a verb (Audit / Audits)
  • Trailing period on the description
  • Link target is the canonical repo URL

Happy to adjust wording, ordering, or section placement; ping me on this PR.


If you'd rather decline, no hard feelings. Thanks for the list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant