Pipeline Guard
PipelineGuard is a browser-based DevSecOps security preflight scanner built for fast repository-level review without uploading your source code.
DROP IN A REPOSITORY ZIP
PipelineGuard locally inventories and analyzes source/configuration files, skipping common generated/vendor trees and binary assets.
WHAT IT SCANS
• GitHub Actions / CI trust boundaries
• Dockerfiles and container hardening
• Kubernetes workload security
• Terraform / IaC exposure
• npm, Python, NuGet, Maven and Gradle dependency hygiene
• secrets and credential-like material
• cross-file compound risks
• optional known-vulnerability lookup through OSV
WHAT YOU GET
• deterministic 0–100 security posture score
• prioritized findings with line-level evidence
• remediation guidance
• whole-repository correlation
• false-positive suppressions with required justification + expiration
• auditable Exception Register
• exportable standalone HTML report
• 60-second guided demo
NEW IN v0.6.1
• clearer Local-first privacy language
• System Status diagnostics
• one-click Test Relay + OSV check
• frontend/relay version-mismatch detection
• browser capability checks for ZIP, storage, clipboard, downloads and live networking
PRIVACY
Repository extraction and static analysis happen locally in the browser. Optional live advisory checks send only exact package coordinates when explicitly requested; repository/source contents are not sent to the PipelineGuard relay.
PipelineGuard is a heuristic preflight scanner, not a penetration test or replacement for full enterprise SAST/SCA/CSPM tooling.

Leave a comment
Log in with itch.io to leave a comment.