Pipelines run with broad permissions, pull in third-party actions, and handle your secrets, yet they rarely get reviewed the way application code does. Pragma Core scans your pipeline definitions every day across five platforms, classifies what it finds by severity, and tracks each issue from the day it appears to the day it is fixed.
Enable scanning on a repository and the platform takes it from there. No SCM token to wire up, no pipeline to instrument, no agent to install.
A real org runs pipelines on more than one platform and carries a tail of misconfigurations at any moment. Here is what the dashboard collapses that into.
Open findings grouped by CI platform and broken down by severity. Hover any bar to see the mix. The platform owns the severity classification, since the open-source engine ships every check without one.
Ranked by severity, with the check ID and the file each one lives in. The fingerprint deliberately ignores line numbers, so editing code above a finding does not churn the row.
| Check | Severity | Issue | File |
|---|---|---|---|
| CKV_GHA_7 | Critical | Shell injection via untrusted input | .github/workflows/ci.yml |
| CKV_GHA_2 | High | Write-all token permissions | .github/workflows/release.yml |
| CKV_GHA_5 | High | Secret piped to curl | .gitlab-ci.yml |
| CKV_GHA_4 | Medium | Action pinned to a mutable tag | .github/workflows/ci.yml |
| CKV_DOCKER_7 | Medium | Base image uses the latest tag | azure-pipelines.yml |
Enable pipeline scanning on a repository and get a clear read on the misconfigurations hiding in your build files.
Choose which categories you are happy to allow. You can change your mind at any time using the Cookie settings link in the footer.