Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/increment

step-security/increment

Action to increment a repository variable. Secure drop-in replacement for action-pack/increment.

10/10
Maintained by StepSecurity
StyraInc/setup-regal

StyraInc/setup-regal

Run Regal, the OPA Rego Linter, as a GitHub Action

3/10
step-security/ansible-galaxy-action

step-security/ansible-galaxy-action

This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.

10/10
Maintained by StepSecurity
open-telemetry/assign-reviewers-action

open-telemetry/assign-reviewers-action

GitHub action to assign reviewers/approvers/etc based on configuration

5/10
MathieuSoysal/hiden-dependency-updater

MathieuSoysal/hiden-dependency-updater

Update automatically dependency that Dependabot can't check.

4/10
MobSF/mobsfscan

MobSF/mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

5/10
step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

An action which adds reviewers to the pull request when the pull request is opened. Secure drop-in replacement for kentaro-m/auto-assign-action.

10/10
greenled/no-merge-commits-check

greenled/no-merge-commits-check

Action for checking no merge commits are present in a pull request

3/10
actions/download-artifact

actions/download-artifact

6/10
rapidsai/shared-actions/dockerhub-script

rapidsai/shared-actions/dockerhub-script

5/10
mikaelvesavuori/standardlint-action

mikaelvesavuori/standardlint-action

This Action makes it even easier to use StandardLint in your GitHub CI runs.

3/10
step-security/actions-hugo

step-security/actions-hugo

GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported. Secure drop-in replacement for peaceiris/actions-hugo.

10/10
Maintained by StepSecurity
step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Secure drop-in replacement for ko-build/setup-ko.

10/10
flexion/check-contributor-allowlist-action

flexion/check-contributor-allowlist-action

2/10
OZI-Project/publish

OZI-Project/publish

OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release

7/10
corentinmusard/otel-cicd-action

corentinmusard/otel-cicd-action

Open Telemetry CI/CD Action

2/10
bsord/helm-push

bsord/helm-push

Push local chart to hosted chart museum repository

3/10
elastic/oblt-actions/slack/send

elastic/oblt-actions/slack/send

7/10
depot/build-push-action

depot/build-push-action

GitHub Action to build and push Docker images with Depot

4/10
OSS-Docs-Tools/code-owner-self-merge

OSS-Docs-Tools/code-owner-self-merge

A GitHub Action for letting CODEOWNERS merge PRs via green PR reviews

3/10