Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
gr1n/setup-poetry
Set up your GitHub Actions workflow with a specific version of Poetry
DeLaGuardo/setup-clojure
GitHub Action to provision clojure's most popular build tools for Linux, Mac OS X and Windows.
step-security/add-pr-comment/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
GitHub Action which adds a comment to a pull request's issue. Secure drop-in replacement for mshick/add-pr-comment.
step-security/release-notes-generator-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Action to auto generate a release note based on your events. Secure drop-in replacement for Decathlon/release-notes-generator-action.
glotaran/pyglotaran-examples
This repository hold examples showcasing the use of the pyglotaran package
microsoft/RichCodeNavIndexer
A GitHub Action that adds rich code navigation to a repo's branches and pull requests.
lfreleng-actions/python-audit-action
Check Python dependencies for known security vulnerabilities
austenstone/copilot-usage
Create copilot usage reports as job summaries, and much more!
grafana/plugin-actions/publish-report
kusaridev/kusari-cli/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Command line interface for Kusari
srebhan/label-milestone-action
Github action to assign milestones to PRs based on labels
andstor/file-reader-action
:page_facing_up: :octocat: GitHub Action to read the contents of a file
step-security/action-discord
🚀 GitHub Action that sends a Discord message. . Secure drop-in replacement for Ilshidur/action-discord.
jenseng/dynamic-uses
Dynamically resolve and use another GitHub action
wpengine/github-action-wpe-site-deploy
A GitHub Action to deploy code directly to WP Engine.
lfreleng-actions/pypi-publish-action
Publishes a Python project to the Python Package Index (PyPI)
gr2m/get-json-paths-action
A GitHub Action to access deep values of JSON strings
Slashgear/action-check-pr-title
Github action to check Pull Request title based on JS Regexp This action in really simple and use Github Action core library base on event of your pull requests No need to install anything on your runner to use it. Simple, fast, reliable 🎉
cisagov/setup-go-package
Composite GitHub action to install a Go package.
Tiryoh/gha-jobid-action
⚙️ GitHub Action to get the current workflow run's Job URL and ID