PipelineSpend
Read-only GitHub Actions Audit

Audit GitHub Actions before changing CI

PipelineSpend inspects GitHub Actions evidence read-only, produces durable findings with provenance, and keeps observed facts separate from estimates, actionability, and verified savings.

Read-only GitHub Audit No Audit-time CI mutation Unknown ≠ $0 Verified only from observed outcomes

What PipelineSpend reads

The current product uses a least-privilege GitHub App with metadata, contents, and Actions read access. It can discover authorized repositories, inspect workflow configuration and bounded run/job history, and retain evidence references needed to reproduce the Audit result.

The Audit path does not require GitHub write access and does not edit workflow files, dispatch jobs, cancel runs, or suppress checks.

What the report means

An observed finding means the detector found evidence matching a defined condition. It does not automatically mean the repository should change. Eligibility requires sufficient evidence and policy authority; actionability requires a safe eligible next step; a verified outcome requires post-change evidence.

  • Observed evidence: what the repository/provider data shows.
  • Estimated opportunity: modeled or calculated upside when a defensible basis exists.
  • Actual prevented work: jobs/runtime demonstrably avoided after an intervention.
  • Verified savings: receipt-backed economic outcome with authoritative pricing/accounting.

Durable evidence instead of repeated collection

When a completed Audit already has sufficient retained evidence, PipelineSpend can serve a durable reread without recollecting provider history or rerunning the Audit engine. This reduces repeated agent and operator work while preserving the original evidence lineage.

Start with evidence, not a write permission

Sign in, authorize the read-only GitHub App, select an eligible repository, and let PipelineSpend build the first useful report from retained CI evidence.

Audit a GitHub repository