7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

Legitify

Open source

Command-line scanner that finds and helps remediate security misconfigurations across GitHub and GitLab organizations, repositories, members and actions.

legitify.dev
Legitify homepage screenshot
GitHub stars
889
Last commit
1 mo ago
Repository age
4 years
Version
v1.0.11
Licence
Apache-2.0
Self-hosted
Yes

About Legitify

Legitify is an open-source tool from Legit Security that checks the security posture of your source-code management systems. It scans GitHub and GitLab assets for misconfigurations and compliance issues so that DevOps and security teams can find risky settings in organizations, repositories, members and actions, and fix them. By default it evaluates its policies against all of these resources and skips archived repositories.

Legitify ships as a Go binary with a set of built-in policies from Legit Security. It can be installed with Homebrew on macOS or Linux, downloaded from the releases page, built from source, or used as a GitHub CLI extension. For automation there is a custom GitHub Action, so it can run as part of a CI process. The main command is analyze, and options let you limit which resources are checked.

Every release since v0.1.6 includes SLSA Level 3 provenance covering the release artifacts and the generated Docker image, which users can verify with the SLSA verifier. The tool is licensed under Apache-2.0. Legit Security also offers a separate application security posture management and software supply chain security product, which the README links to for comparison.

Key features

  • Scans GitHub and GitLab for misconfigurations
  • Built-in security and compliance policies
  • Checks organizations, repositories, members and actions
  • Runs as a CLI, GitHub CLI extension or Action
  • SLSA Level 3 provenance on releases
  • Docker image available

Good fit for

  • →Auditing GitHub organization settings
  • →Running security posture checks in CI
  • →Finding risky repository configurations
Built with
Go
Tags
security
github
gitlab
devsecops
supply-chain
compliance
scanner
golang

Legitify: questions and answers

What is Legitify used for?
Legitify is a command-line scanner that finds and helps remediate security misconfigurations across GitHub and GitLab organizations, repositories, members and actions. It is a good fit for auditing GitHub organization settings, running security posture checks in CI and finding risky repository configurations.
Is Legitify open source?
Yes. Legitify is open source under the Apache-2.0 licence. Its source code is on GitHub at Legit-Labs/legitify and is written mainly in Go.
Is Legitify free?
Yes. Legitify is open source, so the software itself is free to use.
What are some alternatives to Legitify?
Similar open-source tools in the Security category include Gitleaks, TruffleHog and Kubescape. SaaS products in the same category include CheckVibe, Socket and AgentScan.
Is Legitify actively maintained?
Yes. The most recent commit to Legitify was on 31 August 2026, and the latest release is v1.0.11, published on 9 July 2024. The project has 889 stars on GitHub.

Open-source alternatives to Legitify

See all

SaaS alternatives to Legitify

See all