Review closer to the change
Audit a whole repository or focus on the changes in a pull request, while the context is still fresh.
Review authorized GitHub repositories and pull requests at pinned commits. See evidence, understand the risk and decide which fixes to propose before the next release.
Built for development teams
Audit a whole repository or focus on the changes in a pull request, while the context is still fresh.
See the affected file, source link, severity, rationale and available fix preview in one place.
Review suggestions and select fixes yourself. Nothing is pushed to your repository automatically.
Run checks across the authorized repository at a fixed commit and review the resulting findings by severity and file.
Compare a PR with its base commit to focus the review on newly introduced code and dependency changes.
What we inspect
Automated tools provide signals across source, dependencies and repository configuration. Findings still need context and validation.
Semgrep checks supported code for insecure patterns and gives a precise source location.
Gitleaks flags credential candidates. Values are redacted in reports and suspected secrets need validation.
Trivy and OSV compare detected package versions with published advisories; affected versions alone do not prove exploitability.
GitHub Actions checks and available OpenSSF Scorecard signals highlight repository configuration risks.
How it works
Install the GitHub App, authorize the repositories you choose and accept hosted-audit consent.
Choose a complete repository or PR delta. The audit uses a pinned commit so the scope stays clear.
Inspect grouped findings, source links and suggested diffs where a safe patch is available.
Select changes to propose as PRs, or follow practical manual guidance. Recheck the original findings within 30 days.
Export the scope, commit, methodology, findings, evidence and limitations. Findings without a safe automatic diff still include practical remediation guidance.
This is a source-code review, not a pentest of the running application. A dependency advisory is not proof of reachability. Partial scanner coverage is shown, and no fix PR is opened without your request.
Connect an authorized repository and inspect what the scanners found before deciding what to fix.