Secrets
gitleaks detects exposed credentials and API keys
Muninn by Skald Lab scans every PR for secrets, vulnerabilities, and CI/CD pipeline risks — automatically.
- uses: skaldlab/muninn@v0.3.7
with:
token: ${{ secrets.GITHUB_TOKEN }}
Best-in-class open-source tools, orchestrated and normalized into a single finding schema.
gitleaks detects exposed credentials and API keys
Semgrep finds code vulnerabilities across 30+ languages
zizmor catches dangerous GitHub Actions patterns
actionlint + poutine detect workflow risks
OSV-Scanner finds CVEs in your packages
Trivy scans images for vulnerabilities
Checkov finds Terraform and Kubernetes misconfigs
SARIF, JSON, or PR comment — your choice
From zero to full security coverage in minutes.
Drop the Action into any workflow
All 8 scanners run in parallel
PR comments, Security tab, or JSON
Security that fits how teams already ship on GitHub.
AGPL-3.0. Self-hostable. No per-seat pricing.
Works out of the box. Customize via muninn.yml when ready.
Built for GitHub Actions. Results in the Security tab automatically.
Developer security tools from Montevideo, Uruguay.
Skald Lab is an independent software studio focused on practical security for teams that ship on GitHub. We believe every pull request deserves the same depth of scanning that large platform teams run internally — without juggling eight different tools, formats, and CI jobs.
Our flagship project, Muninn, orchestrates gitleaks, Semgrep, zizmor, actionlint, poutine, OSV-Scanner, Trivy, and Checkov into one normalized report. Add a single uses: line to your workflow and Muninn posts PR comments, uploads SARIF to the Security tab, or emits JSON for downstream tooling. Customize scanners and suppressions in muninn.yml when you are ready.
Next steps: copy the workflow snippet above, star muninn on GitHub, or install it from the Marketplace. Questions and vulnerability reports go to security@skaldlab.dev. Follow @skaldlab for release news.
Muninn (Old Norse: “Memory”) was one of Odin’s two ravens, sent out each day to observe the world and return with intelligence. We named our scanner after him — because Muninn never forgets what it finds in your code.