Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

mattermost/action-mattermost-notify

mattermost/action-mattermost-notify

GitHub Action for sending a notification to a Mattermost channel

4/10
notaryproject/notation-action/verify

notaryproject/notation-action/verify

GitHub Actions for signing and verifying artifacts with Notation

6/10
grafana/grafana-github-actions-go/actions/bump-version

grafana/grafana-github-actions-go/actions/bump-version

Grafana GitHub Actions in Golang

3/10
step-security/hide-comment-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/hide-comment-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Action to hide (minimize) comments in pull request. Secure drop-in replacement for int128/hide-comment-action.

10/10
vision-web3/ci-workflows/.github/actions/install-poetry

vision-web3/ci-workflows/.github/actions/install-poetry

3/10
mad9000/actions-find-and-replace-string

mad9000/actions-find-and-replace-string

A GitHub action to execute find-and-replace on strings

2/10
dorny/test-reporter

dorny/test-reporter

Displays test results from popular testing frameworks directly in GitHub

6/10
pytorch/test-infra/test-infra/.github/actions/setup-binary-upload

pytorch/test-infra/test-infra/.github/actions/setup-binary-upload

This repository hosts code that supports the testing infrastructure for the PyTorch organization. For example, this repo hosts the logic to track disabled tests and slow tests, as well as our continuation integration jobs HUD/dashboard.

4/10
redefinedev/redefine-action

redefinedev/redefine-action

This GitHub Action installs, configures & runs Redefine to optimize CI execution time and resources.

3/10
TurboCoder13/py-lintro/.github/actions/setup-env

TurboCoder13/py-lintro/.github/actions/setup-env

Making linters play nice... Mostly.

8/10
arcxp/datadog-service-catalog-metadata-provider

arcxp/datadog-service-catalog-metadata-provider

This repository houses the Datadog Service Catalog Metadata Provider. With this tool you can use GitHub Actions to provide Datadog with the metadata for your service. For more information on what the Datadog Service Catalog is: https://www.datadoghq.com/product/service-catalog/

4/10
denoland/setup-deno

denoland/setup-deno

Set up your GitHub Actions workflow with a specific version of Deno

6/10
grafana/writers-toolkit/publish-technical-documentation-release

grafana/writers-toolkit/publish-technical-documentation-release

Technical documentation guidelines for Grafana Labs documentation

7/10
slsa-framework/slsa-github-generator/.github/actions/sign-attestations

slsa-framework/slsa-github-generator/.github/actions/sign-attestations

Language-agnostic SLSA provenance generation for Github Actions

5/10
hashicorp/actions-hc-releases-promote

hashicorp/actions-hc-releases-promote

GitHub Action for promoting metadata and artifacts using hc-releases

6/10
ndeloof/install-compose-action

ndeloof/install-compose-action

GitHub Action to install Docker Compose v2

3/10
edera-dev/cross/.github/actions/cargo-install-upload-artifacts

edera-dev/cross/.github/actions/cargo-install-upload-artifacts

“Zero setup” cross compilation and “cross testing” of Rust crates

3/10
crqra/conventional-commits-action

crqra/conventional-commits-action

Validate a Pull Request title and commit messages against Conventional Commits guidelines

3/10
rapidsai/node/.github/actions/free-disk-space

rapidsai/node/.github/actions/free-disk-space

GPU-accelerated data science and visualization in node

3/10
malfet/checkout

malfet/checkout

Action for checking out a repo

3/10