Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/shared-workflows/actions/get-vault-secrets

grafana/shared-workflows/actions/get-vault-secrets

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

8/10
filipstefansson/set-npm-token-action

filipstefansson/set-npm-token-action

GitHub Action to create a .npmrc file with your NPM token inside it.

2/10
micronaut-projects/github-actions/pre-release

micronaut-projects/github-actions/pre-release

2/10
getsentry/action-setup-volta

getsentry/action-setup-volta

a github action to set up volta and its caches

4/10
OZI-Project/checkpoint

OZI-Project/checkpoint

OZI action - run dist, test, and lint checks; procure signed test log artifacts

7/10
fallard84/paths-filter

fallard84/paths-filter

Conditionally run actions based on files modified by PR, feature branch or pushed commits

2/10
envoyproxy/toolshed/gh-actions/diskspace

envoyproxy/toolshed/gh-actions/diskspace

6/10
step-security/claude-code-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/claude-code-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Secure drop-in replacement for anthropics/claude-code-action.

10/10
yoavain/Setup-CSC

yoavain/Setup-CSC

Set up your GitHub Actions workflow to add csc.exe into the PATH

2/10
step-security/action-slack-notify

step-security/action-slack-notify

GitHub Action for sending a notification to a Slack channel. Secure drop-in replacement for rtCamp/action-slack-notify.

10/10
Maintained by StepSecurity
grafana/tanka/.github/actions/setup-goversion

grafana/tanka/.github/actions/setup-goversion

Flexible, reusable and concise configuration for Kubernetes

7/10
neondatabase/delete-branch-action

neondatabase/delete-branch-action

4/10
kitabisa/sonarqube-action

kitabisa/sonarqube-action

Integrate SonarQube scanner to GitHub Actions

5/10
mgrybyk-org/allure-report-branch-js-action

mgrybyk-org/allure-report-branch-js-action

Allure Report with history per branch (JS)

5/10
github/lock

github/lock

Lock Action to support deployment locking for the branch-deploy Action

8/10
rfratto/depcheck

rfratto/depcheck

Github Action to create issues for outdated Go deps

2/10
anithapriyanatarajan/plumbing/.github/actions/setup-nightly-infra

anithapriyanatarajan/plumbing/.github/actions/setup-nightly-infra

This repo holds configuration for infrastructure used across the tektoncd org 🏗️

4/10
pandoc/actions/setup

pandoc/actions/setup

4/10
matt-ball/newman-action

matt-ball/newman-action

Use Postman's headless collection runner, Newman, via a GitHub Action.

3/10
bcr-testing/continuous-integration/actions/bcr-pr-reviewer

bcr-testing/continuous-integration/actions/bcr-pr-reviewer

Bazel's Continuous Integration Setup

3/10