Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
actionshub/chef-delivery
Repository for the chef-delivery-action Github Action
elastic/apm-agent-java/.github/workflows/stash
metamask/github-tools/.github/actions/create-release-pr
An assortment of tools interacting with the GitHub API to get metrics for things like PR review comments/reviews
fortify/github-action/internal/fod-logout
Fortify GitHub Actions
tanker187/terraform/.github/actions/go-version
Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.
seemethere/download-artifact-s3
estroz/rerun-actions
A GitHub App that re-runs Action Workflows via PR comment commands.
docker/setup-qemu-action
GitHub Action to install QEMU static binaries
step-security/ansible-galaxy-action/__builder_checkout_dir__/.github/actions/wp-content
This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.
op5dev/tf-via-pr
Plan and apply Terraform/OpenTofu via PR automation, using best practices for secure and scalable IaC workflows.
mheap/github-action-required-labels
Fail the build if/unless a certain combination of labels are applied to a pull request
nanasess/setup-chromedriver
ChromeDriver for use in GitHub Actions
scribemd/docker-cache
Cache Docker Images Whether Built or Pulled
peter-evans/create-issue-from-file
A GitHub action to create an issue using content from a file
coveo/ui-kit/.github/actions/setup-sfdx
Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.
hashicorp/ghaction-import-gpg
DEPRECATED - GitHub action to import GPG private key
mitchellh/vouch/action/manage-by-issue
A community trust management system based on explicit vouches to participate.
asana/push-signed-commits
This composite Github Action uses the createCommitOnBranch GraphQL mutation to allow Github Apps to push 'Verified' commits to Github.
ministryofjustice/hmpps-delius-operational-automation/.github/actions/send-slack-notification
grafana/alloy/_shared-workflows-dockerhub-login/actions/get-vault-secrets
OpenTelemetry Collector distribution with programmable pipelines