Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

google-github-actions/get-secretmanager-secrets

google-github-actions/get-secretmanager-secrets

A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.

7/10
re-actors/checkout-python-sdist

re-actors/checkout-python-sdist

A GitHub Action to unpack a source distribution package (tarball / `.tar.gz`) into the current workspace

3/10
elastic/oblt-actions/oblt-cli/setup

elastic/oblt-actions/oblt-cli/setup

8/10
seanmiddleditch/gha-setup-ninja

seanmiddleditch/gha-setup-ninja

GitHub Action to install the ninja build tool to PATH

6/10
slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

Language-agnostic SLSA provenance generation for Github Actions

5/10
siemens/ix-starter/.github/workflows/actions/install

siemens/ix-starter/.github/workflows/actions/install

Siemens Industrial Experience is a design system for designers and developers, to consistently create the perfect digital experience for industrial software products.

5/10
pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

Testing downstream libraries using pytorch release candidates

6/10
step-security/action-gh-release/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/action-gh-release/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.

10/10
jianlins/llama.cpp/.github/actions/windows-setup-cuda

jianlins/llama.cpp/.github/actions/windows-setup-cuda

LLM inference in C/C++

5/10
grafana/plugin-ci-workflows/actions/plugins/docs/publish

grafana/plugin-ci-workflows/actions/plugins/docs/publish

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

7/10
grafana/shared-workflows/actions/trigger-argo-workflow

grafana/shared-workflows/actions/trigger-argo-workflow

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
erpc/erpc

erpc/erpc

eRPC — fault-tolerant evm rpc proxy

4/10
aquaproj/aqua-installer

aquaproj/aqua-installer

Install aqua securely and quickly

7/10
coveo/plasma/.github/actions/cleanup-demo

coveo/plasma/.github/actions/cleanup-demo

Plasma components implemented with React!

5/10
coveo/ui-kit/.github/actions/playwright-atomic-theming

coveo/ui-kit/.github/actions/playwright-atomic-theming

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

4/10
step-security/allure-report-action

step-security/allure-report-action

Allure Report action with history. Secure drop-in replacement for simple-elf/allure-report-action.

10/10
Maintained by StepSecurity
crate-ci/typos

crate-ci/typos

Source code spell checker

7/10
quotidian-ennui/actions-olio/docker-image-builder

quotidian-ennui/actions-olio/docker-image-builder

It's a gallimaufry of actions

6/10
bruceadams/get-release

bruceadams/get-release

Github Action to get release information based on a tag

3/10
dvega-flexion/tech-radar-generator

dvega-flexion/tech-radar-generator

3/10