gh-guard
Publisher not specified · Claude Code
What this plugin does
GH-Guard hardens CI/CD pipelines for Rust projects. It generates production-tested GitHub Actions workflows with SHA-pinned actions, OIDC-based Trusted Publishing, SLSA L3 provenance, and layered dependency auditing via cargo-deny, Dependabot, and osv-scanner.
Five commands: /audit scans your repo against supply chain best practices, /harden walks you through fixes at three levels (Minimal/Standard/Hardened), /generate creates individual config files, /check-updates catches stale SHA pins, and /verify validates everything before you push.
14 skills provide deep context on Scorecard checks, dangerous workflow patterns, release automation, workspace publishing, fuzz testing, and compromised action incident response. All guidance is informed by real-world incidents including the March 2026 Trivy tag hijacking.
Catalog observations
- Sources
- Community
- Works with
- Claude Code
- Reported installs
- Not provided
- First observed
- 2026-10-03 22:13 UTC
- Last observed
- 2026-10-09 12:03 UTC
Installation counts are reported by Claude Marketplace, not independently verified active users. Observation dates are not release dates. Pricing and account requirements must be checked with the publisher.
Install in Claude Code
Choose a source and review what the plugin adds before installing.
Community
/plugin marketplace add anthropics/claude-plugins-community
/plugin install gh-guard@claude-community
Source evidence
Descriptions and compatibility labels come from the linked sources. Where both sources match, the GitHub description is used because web summaries may be shortened. We have not independently tested the declared capabilities.