Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/tempo/actions/backport

grafana/tempo/actions/backport

Grafana Tempo is a high volume, minimal dependency distributed tracing backend.

7/10
2factorauth/issue-title-action

2factorauth/issue-title-action

2/10
treosh/lighthouse-ci-action

treosh/lighthouse-ci-action

Audit URLs using Lighthouse and test performance with Lighthouse CI.

4/10
contosoenterprise/variable-substitution

contosoenterprise/variable-substitution

Enable GitHub developers to parameterize the values in their config files from a GitHub Action workflow

3/10
scribe-security/action-bom

scribe-security/action-bom

Github action to Collect, Create and Store SBOM evidence

3/10
step-security/openapitools-generator-action

step-security/openapitools-generator-action

Generate a client library using the OpenAPITools Generator. Secure drop-in replacement for openapi-generators/openapitools-generator-action.

10/10
Maintained by StepSecurity
jfheinrich-eu/psono-secret-whisperer

jfheinrich-eu/psono-secret-whisperer

A GitHub Action for securely retrieving secrets from PSONO server

6/10
step-security/upload-release-action

step-security/upload-release-action

Upload files to a GitHub release. Secure drop-in replacement for svenstaro/upload-release-action.

10/10
Maintained by StepSecurity
cycjimmy/semantic-release-action

cycjimmy/semantic-release-action

GitHub Action for Semantic Release

7/10
w3c/spec-prod

w3c/spec-prod

GitHub Action to build ReSpec/Bikeshed specs, validate output and publish to GitHub pages or W3C

6/10
christian-draeger/increment-semantic-version

christian-draeger/increment-semantic-version

3/10
stoplightio/spectral-action

stoplightio/spectral-action

GitHub Action wrapper for Spectral - a JSON/YAML/OpenAPI/AsyncAPI/etc linter with custom rule support.

3/10
google/osv-scanner-action/osv-reporter-action

google/osv-scanner-action/osv-reporter-action

8/10
appleboy/lambda-action

appleboy/lambda-action

GitHub Action for Deploying Lambda code to an existing function

3/10
szkiba/xk6bundler

szkiba/xk6bundler

Bundle k6 with extensions as fast and easily as possible

3/10
chronograph-pe/configure-aws-credentials

chronograph-pe/configure-aws-credentials

Configure AWS credential environment variables for use in other GitHub Actions.

2/10
derberg/npm-dependency-manager-for-your-github-org

derberg/npm-dependency-manager-for-your-github-org

GitHub Action that handles automated update of dependencies in package.json between projects from the same GitHub organization.

4/10
actions-cool/verify-files-modify

actions-cool/verify-files-modify

⚡ Verify PR files modification by GitHub Action.

3/10
crazy-max/ghaction-virustotal

crazy-max/ghaction-virustotal

GitHub Action to upload and scan files with VirusTotal

4/10
grafana/k6-extension-actions/setup-k6registry

grafana/k6-extension-actions/setup-k6registry

Reusable composite GitHub actions to support k6 extension development.

6/10