Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

slsa-framework/slsa-github-generator/actions/delegator/setup-generic

slsa-framework/slsa-github-generator/actions/delegator/setup-generic

Language-agnostic SLSA provenance generation for Github Actions

5/10
timheuer/base64-to-file

timheuer/base64-to-file

Take a base64 string and decodes to a file for use in arguments in later actions.

3/10
tgymnich/fork-sync

tgymnich/fork-sync

🔄 Github action to sync your forks

2/10
step-security/retry/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/retry/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Retries a GitHub Action step on failure or timeout. Secure drop-in replacement for nick-fields/retry.

10/10
pytorch/ao/test-infra/.github/actions/setup-binary-builds

pytorch/ao/test-infra/.github/actions/setup-binary-builds

PyTorch native quantization and sparsity for training and inference

4/10
yonasBSD/toolkit

yonasBSD/toolkit

CI toolkit

5/10
patrickedqvist/wait-for-vercel-preview

patrickedqvist/wait-for-vercel-preview

A github action for waiting for the vercel preview

2/10
italia/publiccode-parser-action

italia/publiccode-parser-action

A simple Github action to validate publiccode.yml

4/10
step-security/s3-actions-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/s3-actions-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Cache to S3 storage with official actions/cache@v2 fallback. Secure drop-in replacement for tespkg/actions-cache.

10/10
grafana/shared-workflows/_shared-workflows-publish-techdocs/actions/techdocs-rewrite-relative-links

grafana/shared-workflows/_shared-workflows-publish-techdocs/actions/techdocs-rewrite-relative-links

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
equinor/xtgeo/.github/actions/setup_xtgeo

equinor/xtgeo/.github/actions/setup_xtgeo

XTGeo Python class library for subsurface Surfaces, Cubes, Wells, Grids, Points, etc

7/10
equitybee/team-label-action

equitybee/team-label-action

⚡️ Auto-label PRs based on the author's team memberships 👥

2/10
achrinza/setup-db2

achrinza/setup-db2

Setup a dev DB2 LUW for plain Linux and GitHub Actions

6/10
extractions/setup-just

extractions/setup-just

🤖 GitHub Action to install the just command runner

5/10
mattaschmann/sync-up-to-codecommit-action

mattaschmann/sync-up-to-codecommit-action

Sync Github to CodeCommit

3/10
vimtor/action-zip

vimtor/action-zip

🗄️ Action for zipping files easily

3/10
step-security/action-semantic-pull-request

step-security/action-semantic-pull-request

GitHub Action that ensures that your PR title matches the Conventional Commits spec. Secure drop-in replacement for amannn/action-semantic-pull-request.

10/10
Maintained by StepSecurity
egibs/melange/melange-src/.github/actions/setup-bubblewrap

egibs/melange/melange-src/.github/actions/setup-bubblewrap

build APKs from source code

5/10
monry/actions-get-project-item-id

monry/actions-get-project-item-id

Get Project Item Id

2/10
xanderhendriks/action-build-stm32cubeide

xanderhendriks/action-build-stm32cubeide

Github action for building STM32 Cube IDE projects

4/10