Pipelineweft: CI Audit app icon

Developer Tools · iPhone & iPad

Pipelineweft: CI Audit

Harden Workflow YAML

$2.99iPhone & iPadData Not Collected

Inside the app

A closer look.

Pipelineweft: CI Audit screenshot 1
iPhone 6.7"
Pipelineweft: CI Audit screenshot 2
iPad Pro 12.9" (3rd gen)
Pipelineweft: CI Audit screenshot 3
iPhone 6.7"
Pipelineweft: CI Audit screenshot 4
iPad Pro 12.9" (3rd gen)
Pipelineweft: CI Audit screenshot 5
iPhone 6.7"
Pipelineweft: CI Audit screenshot 6
iPad Pro 12.9" (3rd gen)
Pipelineweft: CI Audit screenshot 7
iPhone 6.7"
Pipelineweft: CI Audit screenshot 8
iPad Pro 12.9" (3rd gen)

About this app

Made for a clear purpose.

Pipelineweft is a private CI workflow security desk for developers, maintainers, consultants, and small platform teams reviewing the code path that builds, signs, publishes, and deploys their software.

Turn visible YAML risks into a line-level remediation register before privileged automation handles code, tokens, artifacts, or deployments.

KEY FEATURES - Workflow YAML heuristic import - Mutable action reference detection - Broad permission and trigger screen - Untrusted interpolation findings - Per-job least-privilege notes - Workflow-change ownership register - Remediation artifact export - Repository content stays local - Native structured-file or CSV import - Local PDF, workspace JSON, and domain-artifact export - 48 original offline technical reference plates - No account, ads, analytics, tracking, IAP, or subscription

Pipelineweft performs local text heuristics and records review decisions; it does not fetch action source, verify commit provenance, inspect repository settings, or certify a pipeline. Review platform documentation, organization policy, secrets, runners, environments, and called workflows with security owners.