Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/conventional-pr-title-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/conventional-pr-title-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Ensure your PR title matches the Conventional Commits spec. Secure drop-in replacement for aslafy-z/conventional-pr-title-action.

10/10
ansible-community/ansible-lint-action

ansible-community/ansible-lint-action

❗️Replaced by https://github.com/marketplace/actions/run-ansible-lint

6/10
elastic/apm-agent-java/.github/workflows/validate-tag

elastic/apm-agent-java/.github/workflows/validate-tag

8/10
reviewdog/action-eclint

reviewdog/action-eclint

Run eclint with reviewdog

3/10
chronograph-pe/setup-python

chronograph-pe/setup-python

Set up your GitHub Actions workflow with a specific version of Python

2/10
onnx/onnx

onnx/onnx

Open standard for machine learning interoperability

7/10
chainguard-dev/deved-autodocs

chainguard-dev/deved-autodocs

DEPRECATED. Moved to chainguard-dev/images-autodocs

6/10
gcore-github-actions/deploy-container

gcore-github-actions/deploy-container

2/10
Tsukimarf/docs/.github/actions/node-npm-setup

Tsukimarf/docs/.github/actions/node-npm-setup

The open-source repo for docs.github.com

3/10
johnbillion/action-wordpress-plugin-attestation

johnbillion/action-wordpress-plugin-attestation

GitHub Action to generate an attestation for the build provenance of a plugin zip file on wordpress.org

5/10
jontze/action-mdbook

jontze/action-mdbook

A GitHub Action that installs mdBook on a GitHub Runner and supports various plugins like linkcheck, mermaid, toc, open-on-gh, admonish, and katex for enhanced functionality.

3/10
step-security/secure-workflows/Automate-PR

step-security/secure-workflows/Automate-PR

Orchestrate GitHub Actions Security

7/10
pytorch/test-infra/test-infra/.github/actions/setup-miniconda

pytorch/test-infra/test-infra/.github/actions/setup-miniconda

This repository hosts code that supports the testing infrastructure for the PyTorch organization. For example, this repo hosts the logic to track disabled tests and slow tests, as well as our continuation integration jobs HUD/dashboard.

4/10
Git-Hub-Chris/VisualStudioCode/actions/feature-request

Git-Hub-Chris/VisualStudioCode/actions/feature-request

IDE for Windows, Linux, and macOS.

4/10
itchyny/s3-cache-action/restore

itchyny/s3-cache-action/restore

GitHub Action to save cache files and restore them from Amazon S3

4/10
grafana/community-contributions/.github/actions/categorize-pr

grafana/community-contributions/.github/actions/categorize-pr

External contributor PR workflow testing sandbox

4/10
step-security/publish-unit-test-result-action/.github/actions/test

step-security/publish-unit-test-result-action/.github/actions/test

GitHub Action to publish unit test results on GitHub. Secure drop-in replacement for EnricoMi/publish-unit-test-result-action.

10/10
Energinet-DataHub/.github/.github/actions/docker-scan

Energinet-DataHub/.github/.github/actions/docker-scan

Repository containing the common .github items, such as actions, workflows etc.

8/10
slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact

slsa-framework/slsa-github-generator/.github/actions/secure-download-artifact

Language-agnostic SLSA provenance generation for Github Actions

5/10
GabrielBB/xvfb-action

GabrielBB/xvfb-action

Run your tests headlessly ❌🖥️

4/10