Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

taiki-e/create-gh-release-action

taiki-e/create-gh-release-action

GitHub Action for creating GitHub Releases based on changelog.

7/10
elastic/apm-queue/.github/actions/system-test

elastic/apm-queue/.github/actions/system-test

Abstraction layer over Kafka / GCP PubSub Lite to produce and consume records

7/10
slsa-framework/slsa-github-generator/.github/actions/generate-attestations

slsa-framework/slsa-github-generator/.github/actions/generate-attestations

Language-agnostic SLSA provenance generation for Github Actions

5/10
akladiev/labeler

akladiev/labeler

An action for automatically labelling pull requests

2/10
flatherskevin/semver-action

flatherskevin/semver-action

Bump current semantic version based on Git tagging

3/10
coveo/ui-kit/.github/actions/cypress-atomic-screenshots

coveo/ui-kit/.github/actions/cypress-atomic-screenshots

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

5/10
coveo/plasma/.github/actions/test

coveo/plasma/.github/actions/test

Plasma components implemented with React!

5/10
step-security/google-github-auth/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/google-github-auth/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

A GitHub Action for authenticating to Google Cloud. Secure drop-in replacement for google-github-actions/auth.

10/10
elastic/apm-agent-rum-js/.github/workflows/run-test

elastic/apm-agent-rum-js/.github/workflows/run-test

6/10
optum/semver-cli/setup

optum/semver-cli/setup

A technology agnostic cli for common semantic versioning operations.

6/10
microsoft/powerplatform-actions/unpack-solution

microsoft/powerplatform-actions/unpack-solution

Power Platform GitHub Actions automate common build and deployment tasks related to Power Platform. This includes synchronization of solution metadata (a.k.a. solutions) between development environments and source control, generating build artifacts, deploying to downstream environments, provisioning/de-provisioning of environments, and the ability to perform static analysis checks against your solution using the PowerApps checker service.

6/10
step-security/runs-on-cache/restore

step-security/runs-on-cache/restore

Shockingly faster GitHub Action cache with S3 backend. Secure drop-in replacement for runs-on/cache.

10/10
Maintained by StepSecurity
tcort/github-action-markdown-link-check

tcort/github-action-markdown-link-check

Check all links in markdown files if they are alive or dead. 🔗✔️

4/10
elastic/oblt-actions/maven/await-artifact

elastic/oblt-actions/maven/await-artifact

7/10
bnjbvr/cargo-machete

bnjbvr/cargo-machete

Remove unused Rust dependencies with this one weird trick!

6/10
github/licensed-ci

github/licensed-ci

Update and check cached licenses in a GitHub Actions workflow

4/10
aerospike/aerospike-client-java/.github/actions/stage-release-artifacts

aerospike/aerospike-client-java/.github/actions/stage-release-artifacts

Aerospike Java Client Library

5/10
step-security/change-string-case-action

step-security/change-string-case-action

Github Action: Make a string lowercase, uppercase, or capitalized. Secure drop-in replacement for ASzc/change-string-case-action.

10/10
Maintained by StepSecurity
ethpandaops/kurtosis-assertoor-github-action

ethpandaops/kurtosis-assertoor-github-action

3/10
Boomtokn/action-rpc-env

Boomtokn/action-rpc-env

GitHub Action providing RPC_ URLs

3/10