Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

supercharge/mongodb-github-action

supercharge/mongodb-github-action

Use MongoDB in GitHub Actions

7/10
pytorch/rl/test-infra/.github/actions/pull-docker-image

pytorch/rl/test-infra/.github/actions/pull-docker-image

A modular, primitive-first, python-first PyTorch library for Reinforcement Learning.

3/10
grafana/shared-workflows/actions/setup-argo

grafana/shared-workflows/actions/setup-argo

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
zattoo/changelog

zattoo/changelog

📋 GitHub Action to validate CHANGELOG.md files and indicate if the changelog should be modified based on watch folders.

2/10
grafana/docker-slack-message/_shared-workflows-dockerhub-login/actions/get-vault-secrets

grafana/docker-slack-message/_shared-workflows-dockerhub-login/actions/get-vault-secrets

Very simple tool to send Slack messages. Built into a docker image

8/10
step-security/github-api-commit-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/github-api-commit-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Commits changes to the repository through the Github api instead of traditional git commands. Secure drop-in replacement for grafana/github-api-commit-action.

10/10
sasobadovinac/FreeCAD/.github/workflows/actions/runCPPTests/runSingleTest

sasobadovinac/FreeCAD/.github/workflows/actions/runCPPTests/runSingleTest

Fork of the official git master branch of FreeCAD

7/10
Adyen/adyen-swift-public-api-diff

Adyen/adyen-swift-public-api-diff

This tool allows comparing 2 versions of a swift (sdk) project and lists all changes in a human readable way.

6/10
markdown-confluence/markdown-confluence

markdown-confluence/markdown-confluence

Publish your Markdown Files to Confluence

5/10
neondatabase/reset-branch-action

neondatabase/reset-branch-action

3/10
IAreKyleW00t/verified-bot-commit

IAreKyleW00t/verified-bot-commit

✅ GitHub Action for creating signed and verified bot commits

7/10
step-security/file-existence-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/file-existence-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

:file_folder: :octocat: GitHub Action to check for file existence. Secure drop-in replacement for andstor/file-existence-action.

10/10
advanced-security/spdx-dependency-submission-action

advanced-security/spdx-dependency-submission-action

upload an SPDX 2.2 formatted SBOM to GitHub's dependency submission API

6/10
3dwardCh3nG/delete-from-s3-action

3dwardCh3nG/delete-from-s3-action

This is the Github Action that delete object/s from a S3 bucket

4/10
BetaHuhn/repo-file-sync-action

BetaHuhn/repo-file-sync-action

🔄 GitHub Action to keep files like Action workflows or entire directories in sync between multiple repositories.

2/10
neondatabase/schema-diff-action

neondatabase/schema-diff-action

A GitHub Action to post schema changes in your PR comments.

7/10
PandasWhoCode/setup-git-semver

PandasWhoCode/setup-git-semver

Github action to setup git-semver for use in github workflows

6/10
DeterminateSystems/update-flake-lock

DeterminateSystems/update-flake-lock

Automatically refresh your Nix Flakes.

7/10
step-security/update-pr-description

step-security/update-pr-description

GitHub Action to update pull request descriptions. Secure drop-in replacement for nefrob/pr-description.

10/10
Maintained by StepSecurity
chainguard-dev/actions/melange-build-pkg

chainguard-dev/actions/melange-build-pkg

A collection of reusable Github Actions workflows.

8/10