Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

lfit/releng-reusable-workflows/.github/actions/git-commit-message-action

lfit/releng-reusable-workflows/.github/actions/git-commit-message-action

Reusuable workflows developed by LF Release Engineering

7/10
open-telemetry/opentelemetry-ruby-contrib/.github/actions/test_gem

open-telemetry/opentelemetry-ruby-contrib/.github/actions/test_gem

Contrib Packages for the OpenTelemetry Ruby API and SDK implementation.

7/10
step-security/action-send-mail/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/action-send-mail/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

A GitHub Action to send an email to multiple recipients. Secure drop-in replacement for dawidd6/action-send-mail.

10/10
facebook/dotslash-publish-release

facebook/dotslash-publish-release

Create DotSlash files for GitHub releases

5/10
Homebrew/actions/bump-formulae

Homebrew/actions/bump-formulae

🚀 Homebrew's GitHub Actions

7/10
step-security/actions/whereami

step-security/actions/whereami

A collection of reusable Github Actions workflows.

7/10
approved-3rd-party-actions/sticky-pull-request-comment

approved-3rd-party-actions/sticky-pull-request-comment

create comment on pull request, if exists update that comment.

2/10
wei/curl

wei/curl

Wraps the curl CLI to be used in Github Actions

3/10
tonybaloney/pycharm-security

tonybaloney/pycharm-security

Finds security holes in your Python projects from PyCharm and GitHub

4/10
wearerequired/lint-action

wearerequired/lint-action

✨ GitHub Action for detecting and auto-fixing lint errors

3/10
reecetech/version-increment

reecetech/version-increment

GitHub Action that increments semver or calver versions based on git repository tags

6/10
engineerd/configurator

engineerd/configurator

Cross-platform GitHub Action to download, extract, and add to path statically compiled tools

3/10
step-security/background-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/background-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Background commands with log tailing/capture; waits until file/port/socket/http are ready to proceed. Isolates/dedupe errors. Secure drop-in replacement for JarvusInnovations/background-action.

10/10
step-security/test-summary-action

step-security/test-summary-action

Show a helpful summary of test results in GitHub Actions CI/CD workflow runs. Secure drop-in replacement for test-summary/action.

10/10
Maintained by StepSecurity
mamezou-tech/setup-helmfile

mamezou-tech/setup-helmfile

Setup helmfile action

4/10
coveord/auto-approve-action

coveord/auto-approve-action

👍 GitHub Action for automatically approving GitHub pull requests

3/10
azure/login

azure/login

Connect to Azure

8/10
check-run-reporter/action

check-run-reporter/action

A GitHub Action for uploading structured test reports to check-run-reporter.com

3/10
testdriverai/action

testdriverai/action

1/10
redhat-actions/push-to-registry

redhat-actions/push-to-registry

GitHub Action to push a container image to an image registry.

5/10