Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/get-cmake/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/get-cmake/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Install and Cache latest CMake and Ninja for your workflows on your GitHub. Secure drop-in replacement for lukka/get-cmake.

10/10
shalzz/zola-deploy-action

shalzz/zola-deploy-action

Github action for building a Zola site and deploying to Github Pages

5/10
ytanikin/pr-conventional-commits

ytanikin/pr-conventional-commits

3/10
step-security/dynamodb-actions

step-security/dynamodb-actions

Integrate Github Action with Amazon DynamoDB. Secure drop-in replacement for mooyoul/dynamodb-actions.

10/10
Maintained by StepSecurity
super-linter/super-linter/slim

super-linter/super-linter/slim

Combination of multiple linters to run as a GitHub Action or standalone

10/10
JoftheV/workers-sdk/.github/actions/install-dependencies

JoftheV/workers-sdk/.github/actions/install-dependencies

⛅️ Home to Wrangler, the CLI for Cloudflare Workers®

3/10
step-security/ghaction-import-gpg/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/ghaction-import-gpg/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

GitHub Action to import a GPG key. Secure drop-in replacement for crazy-max/ghaction-import-gpg.

10/10
aerospike/aerospike-client-java/.github/actions/publish-to-jfrog

aerospike/aerospike-client-java/.github/actions/publish-to-jfrog

Aerospike Java Client Library

5/10
golangci/golangci-lint-action

golangci/golangci-lint-action

Official GitHub Action for golangci-lint from its authors

9/10
op5dev/prompt-ai

op5dev/prompt-ai

AI inference request GitHub Models via this GitHub Action.

6/10
advanced-security/sarif-toolkit/relativepaths

advanced-security/sarif-toolkit/relativepaths

All things SARIF, as an Action

7/10
elastic/elastic-otel-python/.github/actions/env-install

elastic/elastic-otel-python/.github/actions/env-install

8/10
spotdemo4/bumper

spotdemo4/bumper

git semantic version conventional commit bumper

4/10
fathym/github-tag-action

fathym/github-tag-action

A Github Action to tag a repo on merge.

3/10
JoshStern/push-md-to-notion

JoshStern/push-md-to-notion

Push Markdown to Notion

0/10
grafana/plugin-ci-workflows/actions/internal/plugins/publish/check-artifacts

grafana/plugin-ci-workflows/actions/internal/plugins/publish/check-artifacts

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

7/10
coveo/ui-kit/.github/actions/e2e-atomic-screenshots

coveo/ui-kit/.github/actions/e2e-atomic-screenshots

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

5/10
gagoar/invoke-aws-lambda

gagoar/invoke-aws-lambda

GitHub action to invoke AWS lambda

4/10
nais/deploy/actions/deploy

nais/deploy/actions/deploy

Nais deploy: multi-cluster Kubernetes deployments

5/10
wei/git-sync

wei/git-sync

🔃 A GitHub Action for syncing between two independent repositories using force push

3/10