Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
armbian/build
The official build framework for the Armbian Linux distribution. This repository contains the complete toolchain and scripts required to compile custom OS images from source, including kernel configuration, U-Boot handling, and board-specific tweaks for various ARM and ARM64 single-board computers.
step-security/hide-comment-action
Action to hide (minimize) comments in pull request. Secure drop-in replacement for int128/hide-comment-action.
contentful/create-contentful-app/.github/actions/public-layout.tsx
Bootstrap a Contentful App
step-security/ansible-galaxy-action/__builder_checkout_dir__/.github/actions/wp-content/uploads/2017/10/relish-video-production.png
This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.
tomasreyes/node/node/.github/actions/install-clang
Node.js JavaScript runtime โจ๐ข๐โจ
asdf-vm/actions/plugins-add
GitHub Actions for the asdf version manager
step-security/action-read-yaml/__builder_checkout_dir__/.github/actions/privacy-check
Custom github action used to read yaml files, supporting multiple keys and variable replacements. Secure drop-in replacement for pietrobolcato/action-read-yaml.
sonarsource/sonar-go/.actions/config-gradle
Go Analyzer
prometheus/promci-artifacts/restore
GitHub Actions for artifact persistence between jobs
sonarsource/ci-github-actions/promote
CI/CD GitHub Actions
burningalchemist/action-gh-nfpm
nFPM Packager action
rapidsai/sccache/.github/actions/artifact_failure
Sccache is a ccache-like tool. It is used as a compiler wrapper and avoids compilation when possible. Sccache has the capability to utilize caching in remote storage environments, including various cloud storage options, or alternatively, in local storage.
tomhjp/gh-action-jira-comment
Add a comment to a Jira issue using GitHub actions
intheclouddan/publish-vscode-extension
GitHub action to publish your VS Code Extension to the Open VSX Registry or Visual Studio Marketplace.
zephyrproject-rtos/action-first-interaction
An action for filtering pull requests and issues from first-time contributors
pozetroninc/github-action-get-latest-release
A Github action to get the latest release from another repository.
nvidia/kata-containers/.github/cargo-deny-composite-action
Kata containers is an implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs.
yonasbsd/opendal/.github/actions/fuzz_test
Apache OpenDAL: access data freely.
kong/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact
Language-agnostic SLSA provenance generation for Github Actions
ledgerhq/ledger-live/tools/actions/composites/cache/download
Mono-repository for packages related to Ledger Live and its JavaScript ecosystem.