Fylgyr
0.6.0
Audits GitHub repositories and organizations for supply chain risks mapped to real-world attack campaigns.
Minimum PowerShell version
7.0
Installation Options
Owners
Copyright
(c) Pierre Thoor. All rights reserved.
Package Details
Author(s)
- Pierre Thoor
Tags
PowerShell GitHub Security SupplyChain DevSecOps
Functions
Invoke-Fylgyr Test-ActionPinning Test-ArtifactAttestation Test-ArtifactPoisoning Test-CacheIntegrity Test-BranchProtection Test-CodeOwner Test-CodeScanning Test-DangerousTrigger Test-DependabotAlert Test-DependencyReview Test-EgressControl Test-EnvironmentProtection Test-ForkPullPolicy Test-ForkSecretExposure Test-GitHubAppSecurity Test-IpAllowlist Test-OidcTrust Test-OrgActionRestrictions Test-OrgDefaultPermissions Test-OrgMfaPolicy Test-OAuthAppPolicy Test-OutsideCollaborators Test-PatPolicy Test-PrivateVulnReporting Test-RepoVisibility Test-ReusableWorkflowTrust Test-Rulesets Test-RunnerHygiene Test-AuditLogStreaming Test-PublishIntegrity Test-ScriptInjection Test-SecretScanning Test-SignedCommit Test-TriggerFilter Test-WebhookSecurity Test-WorkflowPermission Test-BinaryArtifact
Dependencies
This module has no dependencies.
FileList
- Fylgyr.nuspec
- Data\attacks.json
- Fylgyr.psd1
- Fylgyr.psm1
- Private\ConvertTo-FylgyrJson.ps1
- Private\ConvertTo-FylgyrSarif.ps1
- Private\Format-FylgyrResult.ps1
- Private\Get-FylgyrOwnerContext.ps1
- Private\Get-MissingTypesEvent.ps1
- Private\Get-RepoTree.ps1
- Private\Get-RunBlock.ps1
- Private\Get-WorkflowFile.ps1
- Private\Get-WorkflowJobBlock.ps1
- Private\Invoke-GitHubApi.ps1
- Private\Write-FylgyrConsole.ps1
- Public\Invoke-Fylgyr.ps1
- Public\Test-ActionPinning.ps1
- Public\Test-ArtifactAttestation.ps1
- Public\Test-ArtifactPoisoning.ps1
- Public\Test-AuditLogStreaming.ps1
- Public\Test-BinaryArtifact.ps1
- Public\Test-BranchProtection.ps1
- Public\Test-CacheIntegrity.ps1
- Public\Test-CodeOwner.ps1
- Public\Test-CodeScanning.ps1
- Public\Test-DangerousTrigger.ps1
- Public\Test-DependabotAlert.ps1
- Public\Test-DependencyReview.ps1
- Public\Test-EgressControl.ps1
- Public\Test-EnvironmentProtection.ps1
- Public\Test-ForkPullPolicy.ps1
- Public\Test-ForkSecretExposure.ps1
- Public\Test-GitHubAppSecurity.ps1
- Public\Test-IpAllowlist.ps1
- Public\Test-OAuthAppPolicy.ps1
- Public\Test-OidcTrust.ps1
- Public\Test-OrgActionRestrictions.ps1
- Public\Test-OrgDefaultPermissions.ps1
- Public\Test-OrgMfaPolicy.ps1
- Public\Test-OutsideCollaborators.ps1
- Public\Test-PatPolicy.ps1
- Public\Test-PrivateVulnReporting.ps1
- Public\Test-PublishIntegrity.ps1
- Public\Test-RepoVisibility.ps1
- Public\Test-ReusableWorkflowTrust.ps1
- Public\Test-Rulesets.ps1
- Public\Test-RunnerHygiene.ps1
- Public\Test-ScriptInjection.ps1
- Public\Test-SecretScanning.ps1
- Public\Test-SignedCommit.ps1
- Public\Test-TriggerFilter.ps1
- Public\Test-WebhookSecurity.ps1
- Public\Test-WorkflowPermission.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.6.0 (current version) | 0 | 5/20/2026 |
| 0.5.0 | 0 | 5/19/2026 |
| 0.4.0 | 9 | 4/12/2026 |
| 0.3.1 | 6 | 4/5/2026 |