Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
jahid11978/openclaw-jahid.ai/.ci-harness/.github/actions/git-owner
jahid
sozercan/dynamo/.github/actions/setup-snapshot-agent
A Datacenter Scale Distributed Inference Serving Framework
step-integration-tests/auto-pdpr-test-48086-12/.github/workflows/install-and-build
Test repository created from policy-based-prs template for integration testing
suzuki-shunsuke/commit-action
GitHub Action to push changes to remote branches by GitHub API. You can create verified commits using GitHub App.
aerospike-community/spring-data-aerospike-starters/.github/actions/publish-to-github
spring-data-aerospike-starters
caffeelake/taipy/.github/actions/gui-test/pyi
Turns Data and AI algorithms into production-ready web applications in no time.
dflook/terraform-destroy
GitHub action to destroy all resources in a terraform workspace
sebrollen/toml-action
launchdarkly/rust-server-sdk/.github/actions/ci
LaunchDarkly Server-Side SDK for Rust
dwisiswant0/setup-go
Set up your GitHub Actions workflow with a specific version of Go
qltysh/qlty-action/install
โถ๏ธ Qlty GitHub Action
graycoreio/github-actions-magento2/image
Github Actions and Workflows that make maintaining Magento2 stores and modules significantly easier.
step-integration-tests/auto-pdpr-test-97527-15/.github/workflows/install-and-build
Test repository created from policy-based-prs template for integration testing
issue-ops/semver
Handles semantic versioning of repository tags
nvidia/nemoclaw/.trusted-ci-actions/.github/actions/ci-plugin-coverage
Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference
grolston/guard-action
GItHub Action for cfn-guard and aws-guard-rules-registry
codacy/codacy-cli-v2-action
caffeelake/cilium/.github/actions/get-cloud-kubeconfig
eBPF-based Networking, Security, and Observability
gensecaihq/shai-hulud-2.0-detector
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
caffeelake/beyla/actions/fill
eBPF-based autoinstrumentation of HTTP and HTTPS services