{"_id":"@agentlaunchopsai/gha-guard","_rev":"8-30f197edd6bd6b0054f1bf894a636690","name":"@agentlaunchopsai/gha-guard","dist-tags":{"latest":"0.1.7"},"versions":{"0.1.0":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.0","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps AI"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.0","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"e53e3077f8998efdcde784eca6eb79e88385ce13","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.0.tgz","fileCount":11,"integrity":"sha512-EzgB+VBNNnGFGL1IeFDaGlFb4PfNfSJOMTn1fI3gmTJTBLd7mCpIMeGSRXgqpe2gBcvYeohfhnQIgtF2wk8/hg==","signatures":[{"sig":"MEQCIH+zNjsGk2TcpzEiohi7mqMsKOj7knIiUQhsiDacpDI6AiAy+ZqtmlG/K+CKOJIsrErWcGf0m6ncAiH+oAJg/MoHlQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":21283},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"27287f85f30dab1a73d364136871d938d9dd98e2","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-0.1.0.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.0_1780862863920_0.33361223264775863","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.1","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps AI"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.1","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"1d1f828eecb5218ae388d6afa3ed3b7449a89411","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.1.tgz","fileCount":11,"integrity":"sha512-pxV7WatgZOdrhlirD6nntjHGk3eGRsbisHS/PncqQk9Egz3/L4nhJ9xyB0EK3ZwcLfHAwegASpMUdmR2v5i5Ig==","signatures":[{"sig":"MEUCIQC6O54MdxJNs367d5/Gwxn/D3TIELf3G5+7+u26GsgkRgIgE9nLrLlrjKQx6W37Y5aZssh/vnk+u1QaGqiG2inAAIk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23001},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"a047fe8fc4dc6d60db0b27dbdabaeb1c3b76f30d","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.1_1780863287128_0.5468589194647868","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.2","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps AI"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.2","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"86d9afc19279d32d686ad8641a90096700113f24","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.2.tgz","fileCount":12,"integrity":"sha512-0F8kmwazhyHTRHVNkc2z3xfopJOXH7rNKOILC5dEFXWHzy0qGRar/LgrrflYUSxGkwgowzkz8WI29oSxuQhGUQ==","signatures":[{"sig":"MEYCIQCHe2c2gaUrrfwgIhCbvVVvpzCtaXT7CLt/Em2uhcNjlgIhAKJ8dzRjTOpYVXDZ0vSsVDdPuyISRDxPSn+MhPc+uobl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25763},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"94cf0faf7997c4d0c44b9d48c45ef077ca20e692","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.2_1780864515787_0.7166021010283996","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.3","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps AI"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.3","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"218dfeeceb756cca4e408197df313435df65088c","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.3.tgz","fileCount":12,"integrity":"sha512-FX7+s76UGBznZYzdMFZes92qPrSTIaJwlmge4X0Z/DqH8U6oQBx24kNhBL23uY8DndiM1QCD9MxEpwfLxzx0Aw==","signatures":[{"sig":"MEUCIQC/Oxp3tsqWyPWhSvyZZDvxxpQ9ksjZ8FINQKKqZAL3nQIgMAIb9U2gQY0UMcw/vgHtScA0cGq/fD+IF2wPLqLrRQk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25905},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"476fb6f20144efb710ebec4a5efffebf9b51db3e","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.3_1780864604252_0.5237230300464695","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.4","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps AI"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.4","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"57293b497ae440828b0435b047f1bb09bed730db","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.4.tgz","fileCount":12,"integrity":"sha512-tihnvat45I58gaHHKjZ0wwC+tsaq7Ysl4uLlf28T08J5vU/fHqCDbmcPMjDBupsuSelj57JwFV+Zq/cKh8h8sw==","signatures":[{"sig":"MEUCIAXmTv6y3HU2+R1Uq8PNNGat+qsEUtp4UQndYVqVSZVEAiEAy6OIxfWo2KLR61j30W8ZBh8940AI4Jy4YLTaCIIikCU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26874},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"6c8c70da79d97c6aa42fee99339268a9d71f30c7","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.4_1780864818985_0.07818613923059847","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.5","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.5","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"a355f76268138d655c00e196f9e6c82b4eef36ce","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.5.tgz","fileCount":12,"integrity":"sha512-z4GmEE5hemNukPomSeXIz0z5eFoRPyS/vWaef8f6l6dXodtpURuhaubwBSHJtvsR+ocXZVxiL/wiW5ucITnseg==","signatures":[{"sig":"MEUCIQDsVgJV9DvHj6fWnOVyyvsQBAFSlalNrQDeLE2vuYKqUQIgJAsXt8QxdISrINQMLff9D7+LjKvJCXk1vrCB6CetZyg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26982},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"05a4377045c6dadf4fb88e9090c4e629d8d547d8","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.5_1780864984254_0.9783332767560704","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.6","keywords":["github-actions","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps"},"license":"MIT","_id":"@agentlaunchopsai/gha-guard@0.1.6","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"bin":{"gha-guard":"src/cli.js"},"dist":{"shasum":"aca80db9581956b47047d46d54091ea896587d92","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.6.tgz","fileCount":12,"integrity":"sha512-vi/YXDtKUo4SCg0ApESLpKOdarqGL5FNRtXNt+ut6qNVAYJI1PTjkh0ZVdZUMHq8mk8C0gs0RGyPjP6Wft9fdg==","signatures":[{"sig":"MEUCIA4ARRX+r/ErJoQIu5CAZkKtTysudaP4ZnoejBwb0/7KAiEA0OC/iUMhvYBYd6PvfwyoYL9UzVpuNLN0GbTFnbKtIbE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27156},"main":"./src/extension.js","type":"module","engines":{"vscode":"^1.90.0"},"gitHead":"7363146281560a39f88ab606a1d23980771337e1","scripts":{"scan":"node src/cli.js .","test":"node --test","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"categories":["Linters","Other"],"_npmVersion":"11.13.0","contributes":{"commands":[{"title":"GHA Guard: Scan Workspace","command":"ghaGuard.scanWorkspace"}]},"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"yaml":"^2.8.1"},"_hasShrinkwrap":false,"devDependencies":{"@vscode/vsce":"^3.6.0"},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"_npmOperationalInternal":{"tmp":"tmp/gha-guard_0.1.6_1780866429303_0.15176486236566533","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@agentlaunchopsai/gha-guard","version":"0.1.7","description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","type":"module","main":"./src/extension.js","bin":{"gha-guard":"src/cli.js"},"scripts":{"test":"node --test","scan":"node src/cli.js .","package:vsix":"node scripts/prepare-vsix.js && cd .vscode-extension && vsce package --no-dependencies --out ../gha-guard-$npm_package_version.vsix","prepublishOnly":"npm test && node src/cli.js ."},"activationEvents":["onLanguage:yaml","onCommand:ghaGuard.scanWorkspace"],"contributes":{"commands":[{"command":"ghaGuard.scanWorkspace","title":"GHA Guard: Scan Workspace"}]},"keywords":["github-actions","github-actions-security","actions-security","workflow-security","supply-chain-security","devsecops","ci-security","cicd-security","sarif","code-scanning","unpinned-actions","pull-request-target","workflow","security","ci","linter"],"author":{"name":"AgentLaunchOps"},"license":"MIT","dependencies":{"yaml":"^2.8.1"},"devDependencies":{"@vscode/vsce":"^3.6.0"},"engines":{"vscode":"^1.90.0"},"categories":["Linters","Other"],"gitHead":"a5e5cab640214809e1bcb0969fe56bddaaeb7d5f","_id":"@agentlaunchopsai/gha-guard@0.1.7","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-T4ljT/2jyC2vO4g/XKIiNuWvmi0yhu2MenERyf9/AiE1jFXjYf5kFaNXzXVM4zZUqeT4G9L8ReWhH29I0OC4FQ==","shasum":"0d85228c728620740eb056410cf5146a36899c12","tarball":"https://registry.npmjs.org/@agentlaunchopsai/gha-guard/-/gha-guard-0.1.7.tgz","fileCount":12,"unpackedSize":28840,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC9278ssMvdDbi/LLQwSiAJN7fRd8gO3tikMqiA0Ms3uwIhAO3WtvSnsXy9V3IONWI3Myn7PCn192rd7sn84ermZZii"}]},"_npmUser":{"name":"agentlaunchops","email":"agentlaunchops@proton.me"},"directories":{},"maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gha-guard_0.1.7_1781635372078_0.17571585556085623"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-07T20:07:43.828Z","modified":"2026-06-16T18:42:52.382Z","0.1.0":"2026-06-07T20:07:44.059Z","0.1.1":"2026-06-07T20:14:47.266Z","0.1.2":"2026-06-07T20:35:15.916Z","0.1.3":"2026-06-07T20:36:44.395Z","0.1.4":"2026-06-07T20:40:19.097Z","0.1.5":"2026-06-07T20:43:04.378Z","0.1.6":"2026-06-07T21:07:09.437Z","0.1.7":"2026-06-16T18:42:52.251Z"},"author":{"name":"AgentLaunchOps"},"license":"MIT","keywords":["github-actions","github-actions-security","actions-security","workflow-security","supply-chain-security","devsecops","ci-security","cicd-security","sarif","code-scanning","unpinned-actions","pull-request-target","workflow","security","ci","linter"],"description":"Scan GitHub Actions workflows for risky defaults and supply-chain footguns.","maintainers":[{"name":"agentlaunchops","email":"agentlaunchops@proton.me"}],"readme":"# GHA Guard\n\nGHA Guard is a small CLI and VS Code extension that scans GitHub Actions\nworkflow files for risky defaults and supply-chain footguns before they reach\nCI.\n\nThe free core runs locally and does not send workflow contents to any service.\n\nUse it as a quick GitHub Actions security audit before enabling new workflows,\nreviewing outside contributions, or adding release and publish automation. It is\ndesigned to catch high-signal CI/CD supply-chain issues early: unpinned actions,\ndangerous `pull_request_target` patterns, broad workflow permissions, missing job\ntimeouts, and shell injection risks from event data.\n\n## What It Checks\n\n- Third-party `uses:` actions that are not pinned to a full commit SHA\n- `pull_request_target` workflows that check out repository code\n- `write-all` or broad `*: write` permissions\n- Jobs without `timeout-minutes`\n- Direct event/input interpolation inside `run:` scripts\n\n## Install\n\n```sh\nnpm install -g @agentlaunchopsai/gha-guard\nnpx @agentlaunchopsai/gha-guard .\n```\n\nLocal development:\n\n```sh\nnpm install\nnpm test\nnode src/cli.js .\n```\n\n## Usage\n\n```sh\ngha-guard .\ngha-guard . --json\ngha-guard . --sarif\ngha-guard . --strict\ngha-guard . --no-fail\nnpx @agentlaunchopsai/gha-guard .\nnpx @agentlaunchopsai/gha-guard . --json\nnpx @agentlaunchopsai/gha-guard . --sarif\nnpx @agentlaunchopsai/gha-guard . --strict\nnpx @agentlaunchopsai/gha-guard . --no-fail\n```\n\nCommon checks:\n\n```sh\n# Audit GitHub Actions workflow supply-chain risk locally\nnpx @agentlaunchopsai/gha-guard .\n\n# Produce SARIF for GitHub code scanning\nnpx @agentlaunchopsai/gha-guard . --sarif --no-fail > gha-guard.sarif\n\n# Flag every unpinned action, including first-party actions\nnpx @agentlaunchopsai/gha-guard . --strict\n```\n\nThe CLI scans `.github/workflows/*.yml` and `.github/workflows/*.yaml`. It exits\nwith `0` when no findings are present, `1` when findings are present, and `2`\nfor runtime errors. SARIF output is compatible with GitHub code scanning upload\nworkflows. By default, `GHA001` ignores first-party `actions/*` and `github/*`\nactions; use `--strict` to flag every unpinned action. Use `--no-fail` when a\nCI job should report findings without failing the build.\n\nGitHub code scanning example:\n\n```yaml\nname: gha-guard\n\non:\n  pull_request:\n  push:\n    branches: [main]\n\njobs:\n  scan-actions:\n    runs-on: ubuntu-latest\n    permissions:\n      security-events: write\n      contents: read\n    timeout-minutes: 5\n    steps:\n      - uses: actions/checkout@v4\n      - run: npx -y @agentlaunchopsai/gha-guard . --sarif --no-fail > gha-guard.sarif\n      - uses: github/codeql-action/upload-sarif@v3\n        with:\n          sarif_file: gha-guard.sarif\n```\n\n## VS Code Extension\n\nThe extension wrapper uses the same scanner as the CLI. It contributes\n`GHA Guard: Scan Workspace` and adds diagnostics when GitHub Actions workflow\nfiles are opened or saved.\n\nBuild the local VSIX:\n\n```sh\nnpm run package:vsix\n```\n\n## Free Core And Pro\n\nThe free core (this package) includes local workflow scanning, text output, JSON\noutput, SARIF output, and CI-friendly exit codes — and always will. It's MIT and\nstands on its own.\n\nIf you want to go further, the optional **[GHA Guard Pro Kit](https://launchagent.gumroad.com/l/auqpvm?utm_source=gha-guard&utm_medium=readme&utm_campaign=pro)** ($29) adds:\n\n- An expanded rule set (more supply-chain and least-privilege checks)\n- A drop-in GitHub Action workflow so scans run on every PR\n- Remediation playbooks: the exact fix for each finding, with examples\n\nThe Pro kit is optional — the free CLI is fully functional without it.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}