Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
eclipse-zenoh/ci/create-release-branch
GitHub Actions and workflows used across eclipse-zenoh
ethlimo/ens-hooks/.github/actions/sca
TypeScript library for encoding, decoding, and executing EIP-8121 hooks with ERC-7930 interoperable addresses
ignacio-circle2/wait-for-status-checks
GitHub Action that waits for check runs
yonasbsd/pouchdb/.github/actions/build-pouchdb
:koala: - PouchDB is a pocket-sized database.
noirbizarre/need-checks
Expect or wait status checks for a commit
bitwarden/android/.github/actions/log-inputs
Bitwarden mobile apps (Password Manager and Authenticator) for Android.
actions-x/commit
check-spelling-sandbox/dependency-review-action
A GitHub Action for detecting vulnerable dependencies in your PRs
d4rkfella/actions/apko-snapshot
nvidia/cccl-gha/.github/actions/workflow-run-job-windows
Github Action infrastructure for CCCL
docker/bake-action/subaction/%3c/script%3e%3cveng13%3e
GitHub Action to use Docker Buildx Bake as a high-level build command
yonasbsd/codeql/.github/actions/os-version
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
lunarmodules/luacheck
A tool for linting and static analysis of Lua code.
envoyproxy/toolshed/actions/github/remnt
yonasbsd/iggy/.github/actions/go/post-merge
Iggy is the persistent message streaming platform written in Rust, supporting QUIC, TCP and HTTP transport protocols, capable of processing millions of messages per second.
viasat::Git-Viasat-Com-PoC::seceng-vionix-stepsecurity-poc-test/github/mszostok-codeowners-validator
Mirror from https://github.com/mszostok/codeowners-validator
docker-practice/actions-setup-docker
Set up your GitHub Actions workflow with a specific version(18.09,19.03,20.10,nightly) of Docker ON Linux/macOS
firedancer-io/firedancer/.github/actions/submodule-init
Firedancer is Jump Crypto's Solana validator software.
bokuweb/sakimori/comment
Cross-platform supply-chain guard for CI: supervised-run audit/block (eBPF/ETW) + minimum-release-age proxy & lockfile check for npm, cargo, PyPI, NuGet.
toolmantim/release-drafter
Drafts your next release notes as pull requests are merged into master.