Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
octodemo/philips-actions-workshop/.github/actions/custom-js-action
jjchange10/test-actions/.github/actions/github-api-test-action
step-security/action-markdownlint/__builder_checkout_dir__/.github/actions/secure-download-artifact
Run markdownlint with reviewdog. Secure drop-in replacement for reviewdog/action-markdownlint.
actions/runner
The Runner for GitHub Actions :rocket:
scribe-security/action-slsa
Collect, Create and Store SLSA provenance evidence
ministryofjustice/laa-submit-a-bulk-claim/.github/actions/ecr-update-image-tags
Web application for bulk upload of claims data
mattnotmitt/doxygen-action
GitHub Action for generating Doxygen documentation for your projects.
actionshub/chef-delivery
Repository for the chef-delivery-action Github Action
elastic/apm-agent-java/.github/workflows/stash
devantler-tech/actions/setup-ksail-action
Actions designed to streamline CI/CD processes.
step-security/set-github-variable/__builder_checkout_dir__/.github/actions/secure-download-artifact
Use this Github Action to update a variable in your Github Action Workflows for your repository. Secure drop-in replacement for mmoyaferrer/set-github-variable.
metamask/github-tools/.github/actions/create-release-pr
An assortment of tools interacting with the GitHub API to get metrics for things like PR review comments/reviews
fortify/github-action/internal/fod-logout
Fortify GitHub Actions
tanker187/terraform/.github/actions/go-version
Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.
space-wizards/submodule-dependency
GitHub action to checkout submodule changes that are required for a pull request
seemethere/download-artifact-s3
estroz/rerun-actions
A GitHub App that re-runs Action Workflows via PR comment commands.
bokuweb/sakimori
Cross-platform supply-chain guard for CI: supervised-run audit/block (eBPF/ETW) + minimum-release-age proxy & lockfile check for npm, cargo, PyPI, NuGet.
launchdarkly/js-core/actions/run-example
LaunchDarkly monorepo for JavaScript SDKs
1password/load-secrets-action/image
Load secrets from 1Password into your GitHub Actions jobs