Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
open-telemetry/assign-reviewers-action
GitHub action to assign reviewers/approvers/etc based on configuration
MathieuSoysal/hiden-dependency-updater
Update automatically dependency that Dependabot can't check.
MobSF/mobsfscan
mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
An action which adds reviewers to the pull request when the pull request is opened. Secure drop-in replacement for kentaro-m/auto-assign-action.
greenled/no-merge-commits-check
Action for checking no merge commits are present in a pull request
actions/download-artifact
rapidsai/shared-actions/dockerhub-script
ministryofjustice/hmpps-assess-risks-and-needs-github-actions/.github/actions/cypress/merge_timings
Reusable Github workflows and actions across the ARNS space (bootstrapped 2025-02-24)
mikaelvesavuori/standardlint-action
This Action makes it even easier to use StandardLint in your GitHub CI runs.
manticoresoftware/paths-filter
Conditionally run actions based on files modified by PR, feature branch or pushed commits
step-security/actions-hugo
GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported. Secure drop-in replacement for peaceiris/actions-hugo.
step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Secure drop-in replacement for ko-build/setup-ko.
pilosus/action-pip-license-checker
GitHub Action for license compliance: Python, JavaScript, iOS, Android and more.
flexion/check-contributor-allowlist-action
OZI-Project/publish
OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release
corentinmusard/otel-cicd-action
Open Telemetry CI/CD Action
bsord/helm-push
Push local chart to hosted chart museum repository
elastic/oblt-actions/slack/send
depot/build-push-action
GitHub Action to build and push Docker images with Depot
OSS-Docs-Tools/code-owner-self-merge
A GitHub Action for letting CODEOWNERS merge PRs via green PR reviews