Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
grafana/k6dist
k6 distribution builder
approved-3rd-party-actions/skip-duplicate-actions
Save time and cost when using GitHub Actions
citation-file-format/cffconvert-github-action
GitHub action to validate CITATION.cff files, and convert to other citation formats.
python-semantic-release/publish-action
GitHub Action to publish assets to a release
jakejarvis/cloudflare-purge-action
🗑️ GitHub Action to purge a website's cache via the Cloudflare API
contributor-assistant/github-action
CLA Assistant GitHub Action
triat/terraform-security-scan
Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec
harden-runner-canary/kyverno/.github/actions/kyverno-wait-ready
Kubernetes Native Policy Management
step-security/ghaction-import-gpg
GitHub Action to import a GPG key. Secure drop-in replacement for crazy-max/ghaction-import-gpg.
Prateek-stepsecurity/harden-runner
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
step-security/setup-kubectl/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
GitHub Action for installing Kubectl. Secure drop-in replacement for Azure/setup-kubectl.
redhat-actions/buildah-build
GitHub Action to use 'buildah' to build a container image.
spotdemo4/nix-simple-cache-action/.github/actions/init
saves and restores the nix store to/from the actions cache
hmarr/auto-approve-action
👍 GitHub Action for automatically approving GitHub pull requests
step-security/setup-ko
Secure drop-in replacement for ko-build/setup-ko.
pytorch/data/test-infra/.github/actions/pull-docker-image
A PyTorch repo for data loading and utilities to be shared by the PyTorch domain libraries.
ljharb/actions/node/prepublish
GitHub actions I use for CI.
nightfallai/nightfall_dlp_action
GitHub Data Loss Prevention (DLP) Action: Scan Pull Requests for sensitive data, like credentials & secrets, PII, credit card numbers, and more.
h0x0er/jaeger/.github/actions/setup-branch
CNCF Jaeger, a Distributed Tracing Platform
actions4git/add-commit-push
✨ Automagically git add, git commit, and git push