Legitify by Legit Security is an open-source security tool designed for GitHub and GitLab users to automatically discover insecure configurations. It connects via an access token and detects issues across various resource types, including member, repository, actions, and organization. Users can scan by specific instance or resource type or an entire organization or group across all resource types. Legitify scans GitHub implementations via the command line to detect security issues in configurations and settings. It can be used across any size GitHub organization. Detected security issues are listed with descriptions and severity, along with threat examples and remediation steps. Security scores are also provided. Legitify is integrated with OSSF Scorecard to assess the security posture of repositories using the Security Scorecard framework. It supports major SCMs, CI/CD systems, and package registries. Policy drifts detection can be detected periodically through Legitify's GitHub Action, and users can get real-time alerts when a misconfiguration is introduced. It also includes SDLC assets management, issue and policy management, and Code To Cloud context for smarter prioritization. Workspaces and product groups, ticketing and alerting with Jira, Slack, and more are supported. Import APIs and integrations with SAST, SCA, and other testing solutions are available.