Pipeline auditor
Reads your pipeline definitions and settings every day and tells you what changed: an action no longer pinned, a token that grew, a runner now shared.
What it watches
- Third-party actions
Actions and plugins pinned to a commit, or floating on a tag that can move.
- Token scopes
Pipeline tokens and their permissions, and the jobs that ask for more than they use.
- Runners
Shared and self-hosted runners, and which repos can schedule work on them.
- Secrets in the pipeline
Where secrets are injected, which jobs can read them and whether forks can.
- Branch and release rules
Protection on main and release branches, required reviews and who can bypass them.
- Drift since last audit
Every change against the baseline your team agreed, with the commit that made it.
One week of drift
What a quiet week looks like from the auditor. None of these broke a build, so none of them was noticed.
- MonBaseline agreed
Twelve repos, every action pinned, tokens read-only by default.
- TueAn action unpinned
A workflow update moved a third-party action from a commit to a tag.
- WedA token grew
The deploy job gained permission to publish packages.
- ThuA runner shared
A self-hosted runner opened to all repos in the organisation.
- FriBack to baseline
Three pull requests, one per change, reviewed and merged.
How it connects
Every module reports to the tower. Some feed each other.
Fed by
The services behind it
The module watches. These services set the station up, with your team, so there is something worth watching.
In development. Early-access teams get it first and shape what it watches.
Join early access →