Force Push Scanner hunts leaked secrets in GitHub force‑push events, enabling red teams to find exposed credentials in ephemeral commits.
github security
GitPhish – OAuth Device Code Phishing for GitHub Repos, Secrets, and CI/CD
GitPhish is an automated tool that exploits GitHub’s OAuth device code flow to gain unauthorized access to repositories, secrets, and CI/CD systems. Learn how it works, how to use it, and how to mitigate this emerging phishing technique.
claws – GitHub Actions Workflow Linter for Secure CI/CD Pipelines
claws is a GitHub Actions workflow linter that helps secure your CI/CD pipeline by identifying misconfigurations, risky triggers, and unsafe action usage before deployment.



