thang.

Awesome Maintainer Defense

Audit repository risks. Review every change.

Inspect local governance, GitHub Actions, and moderation automation. Turn evidence into proposed patches.

Python 3.10+ · MIT · v1.1.1

From local files to a reviewed change

  1. Your repository

    SECURITY.md
    CODEOWNERS
    .github/workflows/*.yml

  2. Offline audit

    maintainer-defense audit .

  3. Findings + evidence

    MD-WF-002 · HIGH
    .github/workflows/
    ci.yml:3

    fix
  4. Proposed patch

    − permissions: write-all
    + permissions: {}

    Human decision
  5. Human decision

    Owner review + CI

    Review, refine, and apply through your normal workflow.

Illustrative workflow. Audit reads local files; fix proposes a diff. Neither applies changes.

Start locally

Python 3.10+ required. Run these commands in your repository.

See example output

Try a ready-made exampleWorkflow → Finding → Proposed patch

Recorded CLI output from a local test fixture. This page does not scan your repository.

Download example

Download and unzip the sample. From the folder containing maintainer-defense-example, run the command below.

Fixture based on the project test corpus · main@29ef246

Governance

Security policy, ownership, issue intake and dependency updates.

GitHub Actions

Token permissions, Action pins and untrusted input.

Moderation

Destructive automation, identity proxies and appeal paths.

Reversible defense kitobserve / balanced / hardened

Preview local policy and workflow controls before applying. Kit assets support English, Vietnamese and Japanese.

observe

Read-only PR analysis and job summary.

balanced

Adds a named failing status check; no comments, labels, closing or locking.

hardened

Adds dependency review and GitHub Actions static analysis.

maintainer-defense install --target . --profile observe --language en

Preview is the default. Only explicit --apply writes kit files. Verify ownership before rolling back; modified files are preserved.

Read the kit guide