Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
appleboy/scp-action
GitHub Action that copy files and artifacts via SSH.
step-security/fetch-gh-release-asset
Github Action to download an asset from a Github release. Secure drop-in replacement for dsaltares/fetch-gh-release-asset.
ad-m/github-push-action
GitHub actions to push back to repository eg. updated code
openzeppelin/openzeppelin-adapters/../__tool_action_dir__
OpenZeppelin Ecosystem Adapters are a set of modular, chain-specific integration packages that bridge the gap between blockchain ecosystems and developer tooling.
step-security/setup-cocoapods
Set up your GitHub Actions workflow with a specific version of Cocoapods. Secure drop-in replacement for maxim-lobanov/setup-cocoapods.
caffeelake/cilium/.github/actions/cilium-config
eBPF-based Networking, Security, and Observability
alexellis/upload-assets
GitHub Action to upload multiple assets to a release
touchlab/ga-update-release-tag
GitHub action to update git tag for a GitHub Release. Used in support of KMMBridge publishing.
actions-security-demo/script-injection/pkg/build/actions/bump-version
step-security/helm-gh-pages/__builder_checkout_dir__/.github/actions/secure-download-artifact
A GitHub Action for publishing Helm charts to Github Pages. Secure drop-in replacement for stefanprodan/helm-gh-pages.
coinbase/cdp-sdk/.github/actions/fetch-docs-artifact
Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys.
caffeelake/llvm-project/workflows-main/.github/workflows/release-binaries-save-stage
The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.
zaproxy/action-full-scan
A GitHub Action for running the ZAP Full scan
oracle-actions/setup-java
GitHub Action to download and install Oracle's Java Development Kit builds
actions-rs/toolchain
๐ ๏ธ GitHub Action for `rustup` commands
lfreleng-actions/gerrit-clone-action
Action to bulk clone (in parallel) an entire Gerrit server repository hierarchy
asyncapi/.github/.github/actions/get-node-version-from-package-lock
Location of all reusable community health files
pytorch/pytorch/pytorch/.github/actions/ecr-login
Tensors and Dynamic neural networks in Python with strong GPU acceleration
step-security/create-pull-request/__builder_checkout_dir__/.github/actions/secure-download-artifact
A GitHub action to create a pull request for changes to your repository in the actions workspace. Secure drop-in replacement for peter-evans/create-pull-request.
proyecto-chaucha/chaucha-gha-wallet-generator
Chaucha functions for usage with Github Actions