Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/mongodb-github-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/mongodb-github-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Use MongoDB in GitHub Actions

10/10
mattallty/jest-github-action

mattallty/jest-github-action

Jest action adding checks with annotations to your pull requests and coverage table as comments

2/10
github/codeql-action/upload-sarif

github/codeql-action/upload-sarif

Actions for running CodeQL analysis

8/10
Samsung/CredSweeper

Samsung/CredSweeper

CredSweeper is a tool to detect credentials in any directories or files. CredSweeper could help users to detect unwanted exposure of credentials (such as token, passwords, api keys etc.) in advance. By scanning lines, filtering, and using AI model as option, CredSweeper reports lines with possible credentials, where the line is, and expected type o

7/10
distroless/actions/apko-build

distroless/actions/apko-build

GitHub actions for the chainguard-images

7/10
EPMatt/reviewdog-action-tsc

EPMatt/reviewdog-action-tsc

Run tsc with reviewdog :dog:

4/10
grafana/alloy/actions/backport

grafana/alloy/actions/backport

OpenTelemetry Collector distribution with programmable pipelines

8/10
reviewdog/action-nimlint

reviewdog/action-nimlint

Run nim check with reviewdog

5/10
oxsecurity/megalinter

oxsecurity/megalinter

🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.

8/10
s-weigand/setup-conda

s-weigand/setup-conda

This action adds the `conda` command from the on the worker preinstalled miniconda version to the known shell commands.

6/10
tomhjp/gh-action-jira-search

tomhjp/gh-action-jira-search

GitHub Action to search for a specific Jira issue with JQL

3/10
Mercymeilya/last-workflow-status

Mercymeilya/last-workflow-status

4/10
Malcolmnixon/Setup-VSTest

Malcolmnixon/Setup-VSTest

Set up your GitHub Actions workflow to add VSTest.Console.exe into the PATH

2/10
atlassian/gajira-comment

atlassian/gajira-comment

3/10
crazy-max/.github/.github/actions/docker-scout

crazy-max/.github/.github/actions/docker-scout

4/10
tor-actions/setup-tor

tor-actions/setup-tor

Set up your GitHub Actions workflow with a specific version of Tor

2/10
Azbagheri/shell-linter

Azbagheri/shell-linter

A Github Action for ShellCheck

5/10
panther-labs/github-asana-action

panther-labs/github-asana-action

Github Action to integrate Asana and Github

3/10
Mattraks/delete-workflow-runs

Mattraks/delete-workflow-runs

An action to delete workflow runs in a repository.

4/10
ljharb/actions/node/run

ljharb/actions/node/run

GitHub actions I use for CI.

4/10