step-security / trivy-compromise-scanner
PublicScan for workflow runs that are impacted by trivy action compromise
A scanning tool that reviews GitHub project workflow logs for evidence of using compromised versions of a specific security action during a brief supply chain incident.
How It Works
You learn about a short-lived compromise in a popular security tool called Trivy that might have affected GitHub projects.
You download and set up this simple scanner on your computer to check your own projects.
You link your GitHub account with a secure permission check to ensure it can peek at your project histories without issues.
You pick specific projects or your whole team folder to scan for any risky tool usage during that alert time.
You launch the check, watch a progress bar as it reviews workflow histories, and it pauses smartly if needed to avoid overload.
You get a clear summary table plus detailed file listing any matches with links to the exact runs.
You now know exactly which runs used the compromised version, with links to update and secure everything.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.