Skip to content

project

taint-trail

Command-line tool that traces untrusted GitHub Actions expressions through workflows, composite actions and the scripts they call, reporting each hop as a file and line plus a verdict for where the value ends up.

Current clusters