Audit a GitHub Actions workflow against the four CISA secure software development attestation sections and the NIST SSDF practices behind them. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
14 rules, four CISA attestation sections, one workflow file
A US application-security contractor bills roughly 150-250 an hour to review and re-pin a release pipeline by hand.
Buy the full version — $29It reads a GitHub Actions workflow file and marks every line that contradicts the CISA Secure Software Development Attestation Common Form, naming the NIST SSDF (SP 800-218) practice ID and the form section behind each mark. It ships 14 rules across the four attestation sections. On the bundled AI-written deploy workflow it returns 8 findings; on the hardened release workflow it returns 0.
Software vendors that sell to United States federal agencies, and the platform or release engineers who own their GitHub Actions pipelines. Under OMB M-22-18 and M-23-16 an agency may use your software only after a chief executive or a designated employee signs the attestation form. Those engineers are the people who have to produce the evidence under that signature.
A general assistant rewrites YAML confidently but does not tell you which attestation section is still empty afterwards. It will pin one action and leave provenance and SBOM missing, and it gives you no line number tied to PS.3.1 that an auditor can follow. This audit is a fixed, readable rule table, not a generated opinion that changes between prompts.
Free: audit the workflow file you have open and list every attestation gap with its practice ID and form section, all 14 rules, all four sections. That job finishes on its own. The full version changes the scope: it audits every workflow in the repository at once and exports one dated evidence table mapped to all four attestation sections.
A United States application-security contractor bills roughly 150 to 250 an hour to review a release pipeline, re-pin actions to commit SHAs and map each control back to an SSDF practice. The full version is 29 once, one licence key per person or team seat, with a 7-day full refund. The free audit costs nothing.
One question, answered by the person who built it. Your email only if you want the answer sent.