Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

Songmu/tagpr

Songmu/tagpr

automatically creates and updates a pull request for unreleased items, tag them when they are merged, and create releases.

6/10
redhat-plumbers-in-action/differential-shellcheck

redhat-plumbers-in-action/differential-shellcheck

🐚 GitHub Action for running ShellCheck differentially

9/10
slsa-framework/slsa-github-generator/.github/actions/secure-upload-folder

slsa-framework/slsa-github-generator/.github/actions/secure-upload-folder

Language-agnostic SLSA provenance generation for Github Actions

5/10
equinor/procosys-js-frontend/.github/actions/pnpm-setup

equinor/procosys-js-frontend/.github/actions/pnpm-setup

Frontend javascript application for Project Completion System (ProCoSys)

4/10
modeseven-lfreleng-actions/python-test-action

modeseven-lfreleng-actions/python-test-action

Tests a Python project and generates coverage reports

5/10
canonical/get-workflow-version-action

canonical/get-workflow-version-action

GitHub action to get commit SHA that GitHub Actions reusable workflow was called with

3/10
tj-actions/glob

tj-actions/glob

:octocat: Github action to match glob patterns with support for matching deleted files.

3/10
camunda/infra-global-github-actions/fossa/pr-check

camunda/infra-global-github-actions/fossa/pr-check

Small Github Actions maintained by Infra team and used by other teams inside Camunda

6/10
sbt/setup-sbt

sbt/setup-sbt

setup-sbt installs the official sbt runner

7/10
step-security/gha-repo-manager

step-security/gha-repo-manager

Manage your Github repo(s) settings and secrets using Github Actions and a yaml file. Secure drop-in replacement for andrewthetechie/gha-repo-manager.

10/10
Maintained by StepSecurity
getsentry/forked-action-lock-threads

getsentry/forked-action-lock-threads

GitHub Action that locks closed issues and pull requests after a period of inactivity

3/10
bencatlab/gha-svu

bencatlab/gha-svu

2/10
hashicorp/packer-github-actions

hashicorp/packer-github-actions

Run HashiCorp Packer as part of your GitHub Actions Workflow

6/10
Reality2byte/checkout

Reality2byte/checkout

Action for checking out a repo

4/10
Templum/govulncheck-action

Templum/govulncheck-action

This action uses govulncheck to perform a scan of the code, afterwards it will parse the output and transform it into an Sarif Report, which will be uploaded to Github using the code-scanning API.

3/10
elastic/apm-aws-lambda/.github/actions/bootstrap

elastic/apm-aws-lambda/.github/actions/bootstrap

A repository for the AWS Lambda extension and other lambda related tools and build scripts.

7/10
fish-shop/indent-check

fish-shop/indent-check

A GitHub action for checking indentation in fish shell files.

8/10
esmf-org/install-esmf-action

esmf-org/install-esmf-action

Install ESMF libraries, modules, and binaries on GitHub Runner

4/10
NVIDIA/gitlab-answer-app/*

NVIDIA/gitlab-answer-app/*

Simple GitHub App that notifies users of the correct way to contribute

2/10
OpenZeppelin/openzeppelin-contracts-upgradeable/.github/actions/storage-layout

OpenZeppelin/openzeppelin-contracts-upgradeable/.github/actions/storage-layout

Upgradeable variant of OpenZeppelin Contracts, meant for use in upgradeable contracts.

7/10