Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/actions-rs-toolchain
๐ ๏ธ GitHub Action for `rustup` commands. Secure drop-in replacement for actions-rs/toolchain.
step-security/conventional-changelog-action/__builder_checkout_dir__/.github/actions/privacy-check
Github Action that generates a changelog with the Conventional Changelog CLI. Secure drop-in replacement for TriPSs/conventional-changelog-action.
anbiona/gale/.github/workflows/runner-setup
Hardened personal server based on secureblue.
dolthub/label-customer-issues
A GitHub Action to apply a label to issues and PRs created by authors who are not members of the team that owns a repo.
pytorch/test-infra/.github/actions/teardown-linux
This repository hosts code that supports the testing infrastructure for the PyTorch organization. For example, this repo hosts the logic to track disabled tests and slow tests, as well as our continuation integration jobs HUD/dashboard.
datadog/integrations-core/.github/actions/setup-test-target-scripts
Core integrations of the Datadog Agent
smartcontractkit/.github/actions/ctf-check-mod-version
reusable GHA workflows and actions
caffeelake/llvm-project/workflows-main/.github/workflows/release-binaries-setup-stage
The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.
anolilab/workflows/step/setup
Shared Github Actions for Node.js projects and Monorepos.
nvidia/nodewright/.github/actions/cosign-verify-release
A Kubernetes Operator to manage Node OS customizations.
kong/changed-files/dir1
fork of changed files git action at a known good commit
marko-k0/ic/.github/actions/bazel
Internet Computer blockchain source: the client/replica software run by nodes
surrealdb/rocksdb/.github/actions/install-maven
A library that provides an embeddable, persistent key-value store for fast storage.
canonical/setup-lxd
A GitHub Action to install & configure LXD on a runner.
freshaengineering/merge-gatekeeper
[DevEx] PR merge control - Branch protection enhancement, merge requirements validation, status check aggregation. | TypeScript, GitHub Actions
rapidsai/pre-commit-hooks/.github/actions/earliest-python-version
step-security/devcontainers-ci
A GitHub Action and Azure DevOps Task designed to simplify using Dev Containers (https://containers.dev) in CI/CD systems. Secure drop-in replacement for devcontainers/ci.
step-security/paths-filter/__builder_checkout_dir__/.github/actions/privacy-check
Conditionally run actions based on files modified by PR, feature branch or pushed commits. Secure drop-in replacement for dorny/paths-filter.
chad-golden/setup-wpr/stop
A GitHub Action that simplifies recording Windows performance traces using Windows Performance Recorder
nvidia/kai-scheduler/.github/actions/setup-e2e-cluster
KAI Scheduler is an open source Kubernetes Native scheduler for AI workloads at large scale