Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
caffeelake/taipy/.github/actions/gui-test/pyi
Turns Data and AI algorithms into production-ready web applications in no time.
dflook/terraform-destroy
GitHub action to destroy all resources in a terraform workspace
sebrollen/toml-action
launchdarkly/rust-server-sdk/.github/actions/ci
LaunchDarkly Server-Side SDK for Rust
qltysh/qlty-action/install
โถ๏ธ Qlty GitHub Action
nvidia/nemoclaw/.trusted-ci-actions/.github/actions/ci-plugin-coverage
Run agents like Hermes and OpenClaw more securely inside NVIDIA OpenShell with managed inference
codacy/codacy-cli-v2-action
caffeelake/cilium/.github/actions/get-cloud-kubeconfig
eBPF-based Networking, Security, and Observability
gensecaihq/shai-hulud-2.0-detector
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
caffeelake/beyla/actions/fill
eBPF-based autoinstrumentation of HTTP and HTTPS services
pytorch/rl/test-infra/.github/actions/setup-nvidia
A modular, primitive-first, python-first PyTorch library for Reinforcement Learning.
step-security/conventional-pr-title-action/__builder_checkout_dir__/.github/actions/privacy-check
Ensure your PR title matches the Conventional Commits spec. Secure drop-in replacement for aslafy-z/conventional-pr-title-action.
blackoretech/ghaction-import-gpg
GitHub Action to import a GPG key
step-security/ansible-galaxy-action/__builder_checkout_dir__/.github/actions/content
This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.
zscalercwp/zscaler-iac-action
step-security/snyk-actions/cocoapods
A set of GitHub actions for checking your projects for vulnerabilities. Secure drop-in replacement for snyk/actions.
cderv/actions/setup-pandoc-nightly
GitHub Actions for the R community
pedrolamas/handlebars-action
:octocat: Transform files in your repository with Handlebars templating!
posthog/check-package-version
Release automatically with this npm package version check by PostHog
catchen/check-git-status-action
Do you check in dependency packages or build artefacts? If yes this GitHub Action helps you ensure they are not out-of-sync.