Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

zyactions/semver

zyactions/semver

A GitHub Action that provides access to the individual parts of a SemVer2 version string.

3/10
tomtom-international/commisery-action

tomtom-international/commisery-action

Scan your commits in your Pull Request against the Conventional Commits standard using Commisery

6/10
lenucksi/adaptive-lighting/.github/workflows/install_dependencies

lenucksi/adaptive-lighting/.github/workflows/install_dependencies

Adaptive Lighting custom component for Home Assistant

3/10
step-security/conventional-pr-title-action/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

step-security/conventional-pr-title-action/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

Ensure your PR title matches the Conventional Commits spec. Secure drop-in replacement for aslafy-z/conventional-pr-title-action.

10/10
andymckay/labeler

andymckay/labeler

3/10
step-security/push-md-to-notion/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/push-md-to-notion/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Push Markdown to Notion. Secure drop-in replacement for JoshStern/push-md-to-notion.

10/10
neondatabase/neon-pkgs/.github/actions/prepare

neondatabase/neon-pkgs/.github/actions/prepare

🐘 CLI to help you hit the ground running without any sign-up. Instantiate a database with a single-command.

6/10
grafana/oncall/.github/actions/install-frontend-dependencies

grafana/oncall/.github/actions/install-frontend-dependencies

Developer-friendly incident response with brilliant Slack integration

6/10
advanced-security/spotbugs-findsecbugs-action

advanced-security/spotbugs-findsecbugs-action

Run SpotBugs with FindSecBugs on Java and other JVM languages (e.g. Scala), and upload the results to GitHub Code Scanning

6/10
intel/ai-containers/.github/scan

intel/ai-containers/.github/scan

This repository contains Dockerfiles, scripts, yaml files, Helm charts, etc. used to scale out AI containers with versions of TensorFlow and PyTorch that have been optimized for Intel platforms. Scaling is done with python, Docker, kubernetes, kubeflow, cnvrg.io, Helm, and other container orchestration frameworks for use in the cloud and on-premise

7/10
jerray/publish-docker-action

jerray/publish-docker-action

GitHub Action used to build, tag and publish docker image to your docker registry

3/10
pytorch/audio/test-infra/.github/actions/setup-nvidia

pytorch/audio/test-infra/.github/actions/setup-nvidia

Data manipulation and transformation for audio signal processing, powered by PyTorch

4/10
crazy-max/.github/.github/actions/gotest-annotations

crazy-max/.github/.github/actions/gotest-annotations

4/10
SonarSource/sonarqube-quality-gate-action

SonarSource/sonarqube-quality-gate-action

7/10
UlisesGascon/openssf-scorecard-monitor

UlisesGascon/openssf-scorecard-monitor

Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts

5/10
rapidsai/shared-actions/telemetry-dispatch-summarize

rapidsai/shared-actions/telemetry-dispatch-summarize

4/10
babenek/CredSweeper

babenek/CredSweeper

CredSweeper is a tool to detect credentials in any directories or files. CredSweeper could help users to detect unwanted exposure of credentials (such as personal information, token, passwords, api keys and etc) in advance. By scanning lines, filtering, and using AI model as option, CredSweeper reports lines with possible credentials, where the line is, and expected type of the credential as a result.

5/10
tj-actions/pg-dump

tj-actions/pg-dump

:octocat: Github action to generate backup of a postgres database.

4/10
step-security/ghaction-import-gpg/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

step-security/ghaction-import-gpg/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

GitHub Action to import a GPG key. Secure drop-in replacement for crazy-max/ghaction-import-gpg.

10/10
grafana/shared-workflows/actions/push-to-gar-docker

grafana/shared-workflows/actions/push-to-gar-docker

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10