Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
anchore/workflows/.github/actions/python
reusable workflows to be used for the oss projects
yonasbsd/grype/.github/actions/bootstrap
A vulnerability scanner for container images and filesystems
yuki0n0/action-appstoreconnect-token
App Store Connect API token generator.
dsanders11/project-actions/get-workflow
A collection of actions for automating GitHub projects
cqlabs/setup-dcm
GitHub Action to install and setup DCM
jonathancombs782/bitcoin/.github/actions/configure-environment
Bitcoin Core integration/staging tree
sasobadovinac/pytorch/.github/actions/teardown-xpu
Tensors and Dynamic neural networks in Python with strong GPU acceleration
redpanda-data/arrow-rs/.github/actions/setup-builder
Official Rust implementation of Apache Arrow
nvidia/aicr/.github/actions/prep-kind-runner
Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes
carabiner-dev/actions/install/ampel-bootstrap
GiitHub actions for various tools in the Carabiner ecosystems
christian-korneck/delete-run-artifacts-action
github action to delete artifacts at the end of a workflow run
viasat::Git-Viasat-Com-PoC::seceng-vionix-stepsecurity-poc-test/github/docker-setup-buildx-action
Mirror from https://github.com/docker/setup-buildx-action
touchlab/sample-group-sanity-check
Github action to do sanity check around org name and group id
ministryofjustice/opg-github-actions/actions/terraform-version
OPG shared GitHub composite actions for workflows.: Managed by opg-org-infra & Terraform
step-security/action-yamllint
GitHub Action - Yaml Lint. Secure drop-in replacement for ibiqlik/action-yamllint.
gurock/trcli-action
CI/CD integration
devantler-tech/ksail/.github/actions/restore-mirror-cache
All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.
octodemo/pull-request-review-action
coveooss/terraform/.github/actions/equivalence-test
Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.
openzeppelin/openzeppelin-contracts/.github/actions/storage-layout
OpenZeppelin Contracts is a library for secure smart contract development.