Scharf – Find and protect ur GitHub Actions from supply-chain attacks
Scharf – Find and protect ur GitHub Actions from supply-chain attacks
Welcome to "Scharf", a blazing-fast security scanner for hardening third-party GitHub actions with mutable references. Using mutable references (version tags, main/master/dev etc.) is a security vulnerability that can result in supply-chain attacks. The recent `tj-actions/changed-files` security incident is scary, so we built a mutable-reference scanner that performs a deep scan across branches to identify all third-party GitHub actions used in organization Git projects. The output report can be exported to CSV or JSON (default). Try it out!
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Litterbox – Defend Against Supply Chain Attacks
Abom – Actions Bill of Materials for GitHub Actions Supply Chains
Supply Chain Resilience AI
Modernising supply-chain traceability and quality assurance
GitHub Actions for Pixela
Sticky Disks in GitHub Actions
Butler – GitHub Actions Oversight Across Organisations
Supply Chain
ChainCentral – AI supply chain planning tool
Manufacturing supply chain visibility, fast.