Secrets
gitleaks detects exposed credentials and API keys
Muninn by Skald Lab scans every PR for secrets, vulnerabilities, and CI/CD pipeline risks β automatically.
- uses: skaldlab/muninn@v1
with:
token: ${{ secrets.GITHUB_TOKEN }}
Best-in-class open-source tools, orchestrated and normalized into a single finding schema.
gitleaks detects exposed credentials and API keys
Semgrep finds code vulnerabilities across 30+ languages
zizmor catches dangerous GitHub Actions patterns
actionlint + poutine detect workflow risks
OSV-Scanner finds CVEs in your packages
Trivy scans images for vulnerabilities
Checkov finds Terraform and Kubernetes misconfigs
SARIF, JSON, or PR comment β your choice
From zero to full security coverage in minutes.
Drop the Action into any workflow
All 8 scanners run in parallel
PR comments, Security tab, or JSON
Security that fits how teams already ship on GitHub.
AGPL-3.0. Self-hostable. No per-seat pricing.
Works out of the box. Customize via muninn.yml when ready.
Built for GitHub Actions. Results in the Security tab automatically.
Muninn (Old Norse: “Memory”) was one of Odin’s two ravens, sent out each day to observe the world and return with intelligence. We named our scanner after him β because Muninn never forgets what it finds in your code.