poutine, a supply chain vulnerability scanner for build pipelines
Created by BoostSecurity.io, poutine is a security scanner that detects
misconfigurations and vulnerabilities in the build pipelines of a repository.
It supports parsing CI workflows from GitHub Actions and Gitlab CI/CD. When
given an access token with read-level access, poutine can analyze all the
repositories of an organization to quickly gain insights into the security
posture of the organization's software supply chain.