Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

bthomas2622/copilot-metrics-export-action

bthomas2622/copilot-metrics-export-action

GitHub Action to export metrics from the GitHub Copilot Metrics API into csv files

2/10
andyl-technologies/github-actions/setup-devenv

andyl-technologies/github-actions/setup-devenv

Common actions for ANDYL's Rust-related configurations

2/10
pSub/nixpkgs/.github/actions/checkout

pSub/nixpkgs/.github/actions/checkout

Nix Packages collection

3/10
grafana/grafana/actions/pr-checks

grafana/grafana/actions/pr-checks

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

6/10
skills/action-text-variables

skills/action-text-variables

Load a text file and replace mustache style variables. Returns modified text as an output for use in other actions.

6/10
grafana/shared-workflows/actions/cleanup-branches

grafana/shared-workflows/actions/cleanup-branches

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
Entle/action-pagerduty-alert

Entle/action-pagerduty-alert

2/10
chronograph-pe/automerge-action

chronograph-pe/automerge-action

GitHub action to automatically merge pull requests that are ready

2/10
checkmarx/kics

checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

6/10
anysphere/alls-green

anysphere/alls-green

A check for whether the dependency jobs are all green.

3/10
egibs/actions/matrix-extra-inputs

egibs/actions/matrix-extra-inputs

A collection of reusable Github Actions workflows.

3/10
HL7/bidi-checker-action

HL7/bidi-checker-action

A GitHub action that checks for bi-directional unicode characters.

2/10
step-security/delete-untagged-ghcr-action

step-security/delete-untagged-ghcr-action

Action for delete containers from Github container registry. Secure drop-in replacement for Chizkiyahu/delete-untagged-ghcr-action.

10/10
Maintained by StepSecurity
ZedThree/clang-tidy-review/post

ZedThree/clang-tidy-review/post

Create a pull request review based on clang-tidy warnings

5/10
danger/danger-js

danger/danger-js

⚠️ Stop saying "you forgot to …" in code review

4/10
bit-tasks/dependency-update

bit-tasks/dependency-update

Bit component updates lookup task for CI/CD

0/10
step-security/push-md-to-notion

step-security/push-md-to-notion

Push Markdown to Notion. Secure drop-in replacement for JoshStern/push-md-to-notion.

10/10
Maintained by StepSecurity
OPENAI/codex/.github/actions/codex

OPENAI/codex/.github/actions/codex

Lightweight coding agent that runs in your terminal

5/10
Cysharp/Actions/.github/actions/download-artifact

Cysharp/Actions/.github/actions/download-artifact

3/10
johnwason/vcpkg-action

johnwason/vcpkg-action

Simple vcpkg action to build and cache packages

4/10