Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/increment
Action to increment a repository variable. Secure drop-in replacement for action-pack/increment.
StyraInc/setup-regal
Run Regal, the OPA Rego Linter, as a GitHub Action
step-security/ansible-galaxy-action
This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.
open-telemetry/assign-reviewers-action
GitHub action to assign reviewers/approvers/etc based on configuration
MathieuSoysal/hiden-dependency-updater
Update automatically dependency that Dependabot can't check.
MobSF/mobsfscan
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
An action which adds reviewers to the pull request when the pull request is opened. Secure drop-in replacement for kentaro-m/auto-assign-action.
greenled/no-merge-commits-check
Action for checking no merge commits are present in a pull request
actions/download-artifact
rapidsai/shared-actions/dockerhub-script
mikaelvesavuori/standardlint-action
This Action makes it even easier to use StandardLint in your GitHub CI runs.
step-security/actions-hugo
GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported. Secure drop-in replacement for peaceiris/actions-hugo.
step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Secure drop-in replacement for ko-build/setup-ko.
flexion/check-contributor-allowlist-action
OZI-Project/publish
OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release
corentinmusard/otel-cicd-action
Open Telemetry CI/CD Action
bsord/helm-push
Push local chart to hosted chart museum repository
elastic/oblt-actions/slack/send
depot/build-push-action
GitHub Action to build and push Docker images with Depot
OSS-Docs-Tools/code-owner-self-merge
A GitHub Action for letting CODEOWNERS merge PRs via green PR reviews