Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

seanmiddleditch/gha-setup-ninja

seanmiddleditch/gha-setup-ninja

GitHub Action to install the ninja build tool to PATH

6/10
slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

Language-agnostic SLSA provenance generation for Github Actions

5/10
pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

Testing downstream libraries using pytorch release candidates

6/10
step-security/action-gh-release/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/action-gh-release/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.

10/10
jianlins/llama.cpp/.github/actions/windows-setup-cuda

jianlins/llama.cpp/.github/actions/windows-setup-cuda

LLM inference in C/C++

5/10
grafana/plugin-ci-workflows/actions/plugins/docs/publish

grafana/plugin-ci-workflows/actions/plugins/docs/publish

6/10
grafana/shared-workflows/actions/trigger-argo-workflow

grafana/shared-workflows/actions/trigger-argo-workflow

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
aquaproj/aqua-installer

aquaproj/aqua-installer

Install aqua securely and quickly

7/10
coveo/plasma/.github/actions/cleanup-demo

coveo/plasma/.github/actions/cleanup-demo

Plasma components implemented with React!

5/10
coveo/ui-kit/.github/actions/playwright-atomic-theming

coveo/ui-kit/.github/actions/playwright-atomic-theming

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

4/10
crate-ci/typos

crate-ci/typos

Source code spell checker

7/10
quotidian-ennui/actions-olio/docker-image-builder

quotidian-ennui/actions-olio/docker-image-builder

It's a gallimaufry of actions

6/10
dvega-flexion/tech-radar-generator

dvega-flexion/tech-radar-generator

3/10
elastic/oblt-actions/github/backport-active

elastic/oblt-actions/github/backport-active

7/10
jauderho/git-repo-sync

jauderho/git-repo-sync

Git Repo Sync Remix enables you to synchronize code to other code management platforms, such as GitLab, Gitee, etc.

6/10
sredevopsorg/metabase/.github/actions/prepare-uberjar-artifact

sredevopsorg/metabase/.github/actions/prepare-uberjar-artifact

The simplest, fastest way to get business intelligence and analytics to everyone in your company :yum:

3/10
step-security/get-cmake/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/get-cmake/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Install and Cache latest CMake and Ninja for your workflows on your GitHub. Secure drop-in replacement for lukka/get-cmake.

10/10
shalzz/zola-deploy-action

shalzz/zola-deploy-action

Github action for building a Zola site and deploying to Github Pages

5/10
ytanikin/pr-conventional-commits

ytanikin/pr-conventional-commits

3/10
step-security/dynamodb-actions

step-security/dynamodb-actions

Integrate Github Action with Amazon DynamoDB. Secure drop-in replacement for mooyoul/dynamodb-actions.

10/10
Maintained by StepSecurity