About Legitify
Legitify is an open-source tool from Legit Security that checks the security posture of your source-code management systems. It scans GitHub and GitLab assets for misconfigurations and compliance issues so that DevOps and security teams can find risky settings in organizations, repositories, members and actions, and fix them. By default it evaluates its policies against all of these resources and skips archived repositories.
Legitify ships as a Go binary with a set of built-in policies from Legit Security. It can be installed with Homebrew on macOS or Linux, downloaded from the releases page, built from source, or used as a GitHub CLI extension. For automation there is a custom GitHub Action, so it can run as part of a CI process. The main command is analyze, and options let you limit which resources are checked.
Every release since v0.1.6 includes SLSA Level 3 provenance covering the release artifacts and the generated Docker image, which users can verify with the SLSA verifier. The tool is licensed under Apache-2.0. Legit Security also offers a separate application security posture management and software supply chain security product, which the README links to for comparison.
Key features
- Scans GitHub and GitLab for misconfigurations
- Built-in security and compliance policies
- Checks organizations, repositories, members and actions
- Runs as a CLI, GitHub CLI extension or Action
- SLSA Level 3 provenance on releases
- Docker image available
Good fit for
- →Auditing GitHub organization settings
- →Running security posture checks in CI
- →Finding risky repository configurations
- Built with
- Go
- Tags
- security
- github
- gitlab
- devsecops
- supply-chain
- compliance
- scanner
- golang
Legitify: questions and answers
- What is Legitify used for?
- Legitify is a command-line scanner that finds and helps remediate security misconfigurations across GitHub and GitLab organizations, repositories, members and actions. It is a good fit for auditing GitHub organization settings, running security posture checks in CI and finding risky repository configurations.
- Is Legitify open source?
- Yes. Legitify is open source under the Apache-2.0 licence. Its source code is on GitHub at Legit-Labs/legitify and is written mainly in Go.
- Is Legitify free?
- Yes. Legitify is open source, so the software itself is free to use.
- What are some alternatives to Legitify?
- Similar open-source tools in the Security category include Gitleaks, TruffleHog and Kubescape. SaaS products in the same category include CheckVibe, Socket and AgentScan.
- Is Legitify actively maintained?
- Yes. The most recent commit to Legitify was on 31 August 2026, and the latest release is v1.0.11, published on 9 July 2024. The project has 889 stars on GitHub.
Open-source alternatives to Legitify
See all
Gitleaks
Security
Find secrets with Gitleaks 🔑
MITvs GitGuardian★ 30k
TruffleHog
Security
Find, verify, and analyze leaked credentials
AGPL-3.0vs GitGuardian★ 28k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
tfsec
Security
Tfsec is now part of Trivy
MITvs Aikido Security★ 7k
Trivy
Security
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code rep
Apache-2.0vs Snyk★ 38k
Semgrep
Security
Lightweight static analysis for many languages. Find bug variants with patterns that look
LGPL-2.1vs Snyk★ 17k
SaaS alternatives to Legitify
See all
CheckVibe
Security
Scans live sites for security, SEO and performance issues left behind by AI coding agents
SaaS
Socket
Security
Supply chain security that detects risky open source packages before install
SaaS
AgentScan
Security
Scans AI coding agent skills for security issues and distributes reviewed workflows for Claude Code and others
SaaS
Aikido Security
Security
All-in-one application security platform for code, cloud and runtime scanning
SaaSAudn.AI
Security
Automated external black-box penetration testing for AI agents, endpoints and production systems
SaaS
Checkmarx
Security
Application security testing platform with SAST, SCA and API security
SaaS

