GitHub Actions Permission Auditor avatar

GitHub Actions Permission Auditor

Pricing

from $4.90 / 1,000 page auditeds

Go to Apify Store
GitHub Actions Permission Auditor

GitHub Actions Permission Auditor

Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

Pricing

from $4.90 / 1,000 page auditeds

Rating

0.0

(0)

Developer

junipr

junipr

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

8 days ago

Last modified

Categories

Share

Store Positioning

Store title: GitHub Actions Permission Auditor

Short description: Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

SEO title: GitHub Actions Permission Auditor — technical SEO, web, and domain audit

SEO description: Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening. Use it to find crawlability, indexability, security, metadata, and page-quality issues with evidence-backed rows and audit reports.

Categories: AUTOMATION

Keywords: github, actions, permission, auditor, web/domain audit

Pay-Per-Event Pricing

This actor uses pay-per-event pricing. Event prices include Apify platform usage; users are not expected to pay a separate platform-usage pass-through charge for the configured pricing model.

  • Tier: W1 — Web/domain audit
  • Primary event: page-audited at $0.00490 base
  • Default max charge: $10.00
  • Store discounts: FREE/BRONZE base, SILVER discounted, GOLD deepest approved discount

Event set:

  • actor-start: base $0.00500, GOLD $0.00400. Github Actions Permission Auditor: charged when actor start is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • page-audited: base $0.00490, GOLD $0.00392. Github Actions Permission Auditor: charged when page audited is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • record-extracted: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when record extracted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • finding-emitted: base $0.00372, GOLD $0.00298. Github Actions Permission Auditor: charged when finding emitted is completed. The price includes Apify platform usage; no separate usage pass-through is intended.
  • audit-report-generated: base $0.05000, GOLD $0.04000. Github Actions Permission Auditor: charged when audit report generated is completed. The price includes Apify platform usage; no separate usage pass-through is intended.

The actor accepts actor-start before work, accepts the primary event before each dataset row, and accepts the configured report event before writing report files. If maxChargeUsd or the live PPE limit blocks a charge, the corresponding row or report is not written.

Public Task Concepts

  • Audit GitHub Actions Permission controls on a capped public sample
  • Find high-priority GitHub Actions Permission issues before release
  • Validate GitHub Actions Permission evidence from supplied pages
  • Prioritize GitHub Actions Permission fixes with severity and proof
  • Export GitHub Actions Permission QA rows for client review

Audit GitHub Actions workflow YAML files for token permission scope, risky triggers, third-party action pinning, secret usage patterns, OIDC configuration, and workflow-level permission hardening.

What it does

  • Accept public workflow YAML URLs, raw YAML inputs, or public repository workflow paths.
  • Parse workflow and job-level permissions.
  • Detect broad token permissions, missing explicit permissions, risky pull_request_target usage, unpinned actions, floating action refs, shell injection-prone patterns, secrets exposure patterns, and OIDC permission usage.
  • Emit workflow-level and job-level audit rows with severity, evidence, and recommendations.
  • Generate action reference inventory and permission matrix.

What it does not do

  • No private repository access unless workflow content is supplied.
  • No account modification, exploit generation, secret extraction, CI execution, or official security certification.

Input fields

Primary inputs from the locked actor spec: workflowFiles, workflowUrls, repositoryUrls, rawYamlInputs, defaultPermissionPolicy, allowedActions, requireShaPinnedActions, includeActionInventory, includeTriggerAudit, maxWorkflows, timeoutMs. maxChargeUsd keeps runs capped during production use.

Output fields

Dataset rows include: repositoryUrl, workflowPath, workflowName, jobId, triggerName, ruleId, severity, permissionScope, permissionValue, actionReference, pinnedStatus, usesSecrets, yamlPath, evidence, recommendation, passed.

Starter example

Use examples/input.tiny.json as a small starter input. Keep the first run capped and review the dataset before increasing limits.

Public task examples

  • Run GitHub Actions Permission Auditor on supplied sample data: Run GitHub Actions Permission Auditor on supplied sample data using a small bounded input.
  • Generate a GitHub Actions Permission Auditor QA report: Generate a GitHub Actions Permission Auditor QA report using a small bounded input.
  • Find invalid rows with GitHub Actions Permission Auditor: Find invalid rows with GitHub Actions Permission Auditor using a small bounded input.
  • Create a capped local endpoint readiness check for GitHub Actions Permission Auditor: Create a capped local endpoint readiness check for GitHub Actions Permission Auditor using a small bounded input.
  • Prepare GitHub Actions Permission Auditor output for downstream automation: Prepare GitHub Actions Permission Auditor output for downstream automation using a small bounded input.

Public source provenance

The starter input audits the public actions/checkout test workflow at immutable commit e8d4307400f9427dba7cb98e488d6ab85f1cec5f. Public tasks inspect five upstream workflows from that revision for explicit permissions, trigger risks, action references, and secret-context use.

Reports

  • github-actions-permission-audit.md
  • workflow-permission-matrix.csv
  • third-party-action-inventory.json
  • workflow-trigger-risk-summary.json
  • unpinned-actions.csv

Limitations and safe use

Start with supplied-input runs, then enable live endpoints only with tight caps, domain allowlists, and no secrets in public examples.