Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

patrickedqvist/wait-for-vercel-preview

patrickedqvist/wait-for-vercel-preview

A github action for waiting for the vercel preview

2/10
skills/exercise-toolkit/actions/file-exists

skills/exercise-toolkit/actions/file-exists

Toolkit to standardize and reuse common parts of Skills exercises

9/10
italia/publiccode-parser-action

italia/publiccode-parser-action

A simple Github action to validate publiccode.yml

5/10
step-security/s3-actions-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/s3-actions-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Cache to S3 storage with official actions/cache@v2 fallback. Secure drop-in replacement for tespkg/actions-cache.

10/10
grafana/shared-workflows/_shared-workflows-publish-techdocs/actions/techdocs-rewrite-relative-links

grafana/shared-workflows/_shared-workflows-publish-techdocs/actions/techdocs-rewrite-relative-links

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

7/10
equinor/xtgeo/.github/actions/setup_xtgeo

equinor/xtgeo/.github/actions/setup_xtgeo

XTGeo Python class library for subsurface Surfaces, Cubes, Wells, Grids, Points, etc

7/10
equitybee/team-label-action

equitybee/team-label-action

⚡️ Auto-label PRs based on the author's team memberships 👥

2/10
achrinza/setup-db2

achrinza/setup-db2

Setup a dev DB2 LUW for plain Linux and GitHub Actions

6/10
extractions/setup-just

extractions/setup-just

🤖 GitHub Action to install the just command runner

5/10
mattaschmann/sync-up-to-codecommit-action

mattaschmann/sync-up-to-codecommit-action

Sync Github to CodeCommit

3/10
vimtor/action-zip

vimtor/action-zip

🗄️ Action for zipping files easily

3/10
skymoore/required-approvals

skymoore/required-approvals

Github Action to check PR approvals and codeowners

2/10
step-security/action-semantic-pull-request

step-security/action-semantic-pull-request

GitHub Action that ensures that your PR title matches the Conventional Commits spec. Secure drop-in replacement for amannn/action-semantic-pull-request.

10/10
Maintained by StepSecurity
egibs/melange/melange-src/.github/actions/setup-bubblewrap

egibs/melange/melange-src/.github/actions/setup-bubblewrap

build APKs from source code

5/10
monry/actions-get-project-item-id

monry/actions-get-project-item-id

Get Project Item Id

2/10
xanderhendriks/action-build-stm32cubeide

xanderhendriks/action-build-stm32cubeide

Github action for building STM32 Cube IDE projects

4/10
anysphere/test-reporter

anysphere/test-reporter

Displays test results from popular testing frameworks directly in GitHub

2/10
gr1n/setup-poetry

gr1n/setup-poetry

Set up your GitHub Actions workflow with a specific version of Poetry

4/10
DeLaGuardo/setup-clojure

DeLaGuardo/setup-clojure

GitHub Action to provision clojure's most popular build tools for Linux, Mac OS X and Windows.

4/10
step-security/add-pr-comment/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/add-pr-comment/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

GitHub Action which adds a comment to a pull request's issue. Secure drop-in replacement for mshick/add-pr-comment.

10/10