Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

google-github-actions/deploy-cloudrun

google-github-actions/deploy-cloudrun

A GitHub Action for deploying services to Google Cloud Run.

7/10
elastic/elastic-agent-client/.github/actions/setup

elastic/elastic-agent-client/.github/actions/setup

6/10
step-security/actions/setup-registry

step-security/actions/setup-registry

A collection of reusable Github Actions workflows.

7/10
GitGuardian/gg-shield-action

GitGuardian/gg-shield-action

GitGuardian Shield GitHub Action - Find exposed credentials in your commits

5/10
tomasreyes/attest-build-provenance

tomasreyes/attest-build-provenance

Action for generating build provenance attestations for workflow artifacts

5/10
step-security/setup-vals

step-security/setup-vals

Github Action for installing vals (https://github.com/helmfile/vals). Secure drop-in replacement for jkroepke/setup-vals.

10/10
Maintained by StepSecurity
SonarSource/sonarcloud-github-action

SonarSource/sonarcloud-github-action

Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.

8/10
mavrosxristoforos/get-xml-info

mavrosxristoforos/get-xml-info

Get Information from XML files to use into your GitHub workflows

5/10
MetaMask/github-tools/.github/actions/pr-line-check

MetaMask/github-tools/.github/actions/pr-line-check

An assortment of tools interacting with the GitHub API to get metrics for things like PR review comments/reviews

4/10
chronograph-pe/actions-permissions/monitor

chronograph-pe/actions-permissions/monitor

GitHub token permissions Monitor and Advisor actions

3/10
actions-security-demo/script-injection/actions/commands

actions-security-demo/script-injection/actions/commands

2/10
shundor/python-bandit-scan

shundor/python-bandit-scan

GitHub Action for Bandit SAST

5/10
equinor/oneseismic-api/.github/actions/load_openvds_image

equinor/oneseismic-api/.github/actions/load_openvds_image

Web API for fast access of arbitrary seismic slices from VDS data

6/10
crazy-max/ghaction-docker-buildx

crazy-max/ghaction-docker-buildx

:octocat: GitHub Action to set up Docker Buildx

3/10
kubepug/kubepug-installer

kubepug/kubepug-installer

kubepug-installer GitHub Action

5/10
bryannice/gitactions-slack-notification

bryannice/gitactions-slack-notification

Git Action Slack Notifications From Build Status

4/10
rudderlabs/setup-aws-signer-notation-cli

rudderlabs/setup-aws-signer-notation-cli

This GitHub Action installs Notation CLI with the AWS Signer plugin.

3/10
quantco/ui-actions/version-metadata

quantco/ui-actions/version-metadata

Monorepo for UI related github actions

2/10
step-security/secure-repo/Automate-PR

step-security/secure-repo/Automate-PR

Orchestrate GitHub Actions Security

7/10
intel/ai-containers/apptainer

intel/ai-containers/apptainer

This repository contains Dockerfiles, scripts, yaml files, Helm charts, etc. used to scale out AI containers with versions of TensorFlow and PyTorch that have been optimized for Intel platforms. Scaling is done with python, Docker, kubernetes, kubeflow, cnvrg.io, Helm, and other container orchestration frameworks for use in the cloud and on-premise

7/10