Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

ForAllSecure/mapi-action

ForAllSecure/mapi-action

🤖 Run a Mayhem for API scan in GitHub Actions

2/10
pytorch/test-infra/.github/actions/update-commit-hash

pytorch/test-infra/.github/actions/update-commit-hash

This repository hosts code that supports the testing infrastructure for the PyTorch organization. For example, this repo hosts the logic to track disabled tests and slow tests, as well as our continuation integration jobs HUD/dashboard.

4/10
grafana/github-actions-testrepo/actions/pr-checks

grafana/github-actions-testrepo/actions/pr-checks

4/10
jmuelbert/jm-checkconnect/.github/actions/python-setup

jmuelbert/jm-checkconnect/.github/actions/python-setup

Test connection to Webservers and ntp-servers

6/10
Shopify/filediff

Shopify/filediff

Create a filediff comment to compare file size changes

5/10
kurt-code/gha-properties

kurt-code/gha-properties

Read/Write Values given a properties file.

5/10
Quantco/ui-actions/version-metadata

Quantco/ui-actions/version-metadata

Monorepo for UI related github actions

2/10
contentful/polaris-action

contentful/polaris-action

5/10
vmactions/openbsd-vm

vmactions/openbsd-vm

Use OpenBSD in github actions

6/10
actions-security-demo/harden-runner

actions-security-demo/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

5/10
elastic/cloudbeat/.github/actions/gcp-asset-inventory-ci

elastic/cloudbeat/.github/actions/gcp-asset-inventory-ci

Analyzing Cloud Security Posture

6/10
coveo/ui-kit/.github/actions/cypress-atomic

coveo/ui-kit/.github/actions/cypress-atomic

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

4/10
dagster-io/dagster-cloud-action/actions/utils/dagster-cloud-cli

dagster-io/dagster-cloud-action/actions/utils/dagster-cloud-cli

3/10
azure/webapps-container-deploy

azure/webapps-container-deploy

Enable GitHub developers to deploy to Azure WebApp for containers using GitHub Actions

4/10
geertvdc/setup-hub

geertvdc/setup-hub

Github Action to set up hub CLI

2/10
carloscastrojumo/github-cherry-pick-action

carloscastrojumo/github-cherry-pick-action

GitHub action for cherry pick commits from Pull Requests into Release branchs

3/10
dawidd6/action-send-mail/_next/static/chunks/7514-ce0442a60ce195db.js

dawidd6/action-send-mail/_next/static/chunks/7514-ce0442a60ce195db.js

:gear: A GitHub Action to send an email to multiple recipients

4/10
pytorch/data/test-infra/.github/actions/calculate-docker-image

pytorch/data/test-infra/.github/actions/calculate-docker-image

A PyTorch repo for data loading and utilities to be shared by the PyTorch domain libraries.

3/10
simple-elf/allure-report-action

simple-elf/allure-report-action

Allure Report action with history

5/10
step-security/semver-utils/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/semver-utils/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

One-stop shop for working with semantic versions in your GitHub Actions workflows. Secure drop-in replacement for madhead/semver-utils.

10/10