GitHub App · Free · Open Source

Your repos push code.
We make sure it's yours.

RepoGuard scans every commit for malicious code, blocks dangerous pushes, and opens fix pull requests automatically — before damage reaches your default branch.

repoguard · security scan

Results shown in GitHub check runs and pull requests — no CLI required

0+
Detection Rules
#0
Cost to Install
0+
Typosquat Signatures
<2s
Scan Time per Push
How it works

Install once. Protected forever.

RepoGuard plugs into GitHub's event system. No configuration required — it starts scanning the moment you install it.

STEP 01
🔌

Install on GitHub

One click from the Marketplace. Grant repository access and RepoGuard immediately scans your entire codebase for existing threats.

STEP 02
🔍

Every push is scanned

Each commit triggers a scan of changed files. A GitHub Check Run reports the result — clean or blocked — directly in your pull request.

STEP 03
🔒

Fix PRs opened automatically

When issues are found, RepoGuard opens a detailed pull request with the patches applied, findings explained, and your repo admins requested as reviewers.

Compare Features

How we stack up

Unlike traditional vulnerability checkers, RepoGuard focuses directly on active developer supply chain threat vectors.

Security FeatureRepoGuardDependabotGitHub CodeQL
Instant scan-on-push hooks Yes (Blocked) No (Periodic) Yes (CI Action)
Malware injection rules (RCE, shells) Full coverage (23+) None (CVE database only) Partial static patterns
Package typosquatting scans Yes (100+ signatures) No No
Interactive post-push Auto-Fix PRs Yes (Applies diff) Yes (Updates version) No
Average setup runtime < 30 seconds3 minutes15+ minutes config
Detection coverage

What RepoGuard catches

Rules are written from real attack patterns — not theoretical threats. Every rule maps to a documented malware campaign or CVE-class vulnerability.

CRITICAL
Remote Code Execution

Detects curl|bash and wget|sh patterns — the most common malware delivery mechanism in compromised repos.

CRITICAL
Reverse Shells

Catches bash -i >& /dev/tcp and netcat reverse shell patterns before they reach your default branch.

CRITICAL
Obfuscated Payloads

Identifies base64-encoded eval() chains and obfuscated string array patterns used to hide malicious intent.

CRITICAL
Python Obfuscation

exec(compile()) and dynamic __import__() calls — the standard toolkit for PyPI malware campaigns.

CRITICAL
Workflow Misconfiguration

Flags pull_request_target with PR head checkout — a well-known GitHub Actions vector for fork-based RCE.

HIGH
Crypto Miners

Detects xmrig, stratum+tcp, and cryptonight keywords injected into CI pipelines and scripts.

HIGH
Secret Exfiltration

Catches environment variable reads combined with outbound HTTP calls — the pattern behind most token theft.

HIGH
Typosquatted Packages

Scans package.json and requirements.txt against 100+ known typosquatted npm and PyPI package names.

HIGH
Committed .env Files

Immediately flags .env, .env.production, and .env.local being pushed to any branch.

HIGH
Malicious postinstall

Detects package.json postinstall scripts that make network calls — a supply chain attack staging ground.

HIGH
Dependency Confusion

Detects attempts to hijack internal package scopes with public npm registry uploads.

HIGH
Shell Injections in Actions

Flags dynamic inputs (like github.event.issue.title) directly interpolated in run: steps.

Questions

Frequently Asked Questions

Everything you need to know about setting up RepoGuard.

FREE — NO CREDIT CARD

Your next commit
could be the one that matters.

Takes 30 seconds to install. Works on every repo, every push, immediately.

Install RepoGuard Free →