Gh Guard
GH-Guard hardens CI/CD pipelines for Rust projects. It generates production-tested GitHub Actions workflows with SHA-pinned actions, OIDC-based Trusted Publishing, SLSA L3 provenance, and layered dependency auditing via cargo-deny, Dependabot, and osv-scanner. Five commands: /audit scans your repo against supply chain best practices, /harden walks you through fixes at three levels (Minimal/Standard/Hardened), /generate creates individual config files, /check-updates catches stale SHA pins, and
Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code
Category: Dev Tools & CI — see all ranked ›
- tashan score: 38.0
- Adoption: 1 repos
- Health: active
- GitHub stars: 15
- Contributors: 2
- License: MIT
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · plugin:sbom-tool/gh-guard/gh-guard
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›