Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

bazelbuild/continuous-integration/actions/bcr-pr-reviewer

bazelbuild/continuous-integration/actions/bcr-pr-reviewer

Bazel's Continuous Integration Setup

6/10
coveord/snowpark-java-scala/jira/gajira-issue-update

coveord/snowpark-java-scala/jira/gajira-issue-update

Snowflake Snowpark Java & Scala API

4/10
gradle/actions/dependency-submission

gradle/actions/dependency-submission

A collection of GitHub Actions to accelerate your Gradle Builds on GitHub

8/10
OpenZeppelin/uniswap-hooks/.github/actions/setup

OpenZeppelin/uniswap-hooks/.github/actions/setup

Solidity library for secure and modular Uniswap hooks.

5/10
actions-security-demo/script-injection/.github/workflows/actions/changelog

actions-security-demo/script-injection/.github/workflows/actions/changelog

2/10
sersoft-gmbh/setup-gh-cli-action

sersoft-gmbh/setup-gh-cli-action

A GitHub action that installs or updates the gh CLI

5/10
pytorch/multipy/test-infra/.github/actions/pull-docker-image

pytorch/multipy/test-infra/.github/actions/pull-docker-image

torch::deploy (multipy for non-torch uses) is a system that lets you get around the GIL problem by running multiple Python interpreters in a single C++ process.

3/10
pavelzw/pytest-action

pavelzw/pytest-action

:octocat: GitHub Action to run pytest with GitHub Job Summaries support :snake: :rocket:

5/10
Azure/k8s-deploy

Azure/k8s-deploy

GitHub Action for deploying to Kubernetes clusters

9/10
imjasonh/gke-auth

imjasonh/gke-auth

K8s cred helper and setup without gcloud

3/10
chainguard-dev/actions/donotsubmit

chainguard-dev/actions/donotsubmit

A collection of reusable Github Actions workflows.

8/10
celo-org/viem/.github/actions/setup-wagmi

celo-org/viem/.github/actions/setup-wagmi

TypeScript Interface for Ethereum

5/10
austenstone/actions-playground/.github/actions/hello-world-javascript-action

austenstone/actions-playground/.github/actions/hello-world-javascript-action

Playground for actions

5/10
dflook/terraform-check

dflook/terraform-check

GitHub action to check if there are terraform changes to apply

2/10
step-security/argo-cd-action

step-security/argo-cd-action

GitHub action for executing Argo CD 🦑. Secure drop-in replacement for clowdhaus/argo-cd-action.

10/10
Maintained by StepSecurity
boredland/action-purge-workflow-runs

boredland/action-purge-workflow-runs

removes inactive check suites after a given amount of days without a run

2/10
deepcode-ai/codeql/.github/actions/cache-query-compilation

deepcode-ai/codeql/.github/actions/cache-query-compilation

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

2/10
ParanoidBeing/action-wip-blocker

ParanoidBeing/action-wip-blocker

GitHub Action that blocks WIP PRs

2/10
untitaker/hyperlink

untitaker/hyperlink

Very fast link checker for CI.

4/10
the-commons-project/terragrunt-github-actions

the-commons-project/terragrunt-github-actions

Terraform GitHub Actions

3/10