Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
python-semantic-release/upload-to-gh-release
DEPRECATED: Upload artefacts to GitHub Releases using Python Semantic Release
step-security/helm-gh-pages/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
A GitHub Action for publishing Helm charts to Github Pages. Secure drop-in replacement for stefanprodan/helm-gh-pages.
bazel-contrib/publish-to-bcr
A GitHub app that mirrors releases of your Bazel ruleset to the Central Registry
hacs/action
Repository validator action for HACS
elastic/cloudbeat/.github/actions/aws-asset-inventory-ci
Analyzing Cloud Security Posture
quarto-dev/quarto-actions/setup
yonasBSD/greptimedb/.github/actions/setup-kafka-cluster
An open-source, cloud-native, distributed time-series database with PromQL/SQL/Python supported.
actions-security-demo/script-injection/actions/remove-milestone
PicnicSupermarket/caffeine/.github/actions/run-gradle
A high performance caching library for Java
yonasBSD/grafana/.github/actions/website-sync
The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
transferwise/actions-pr-checker
Github Action to check PR title/description/labels.
grafana/loki/_shared-workflows-dockerhub-login/actions/get-vault-secrets
Like Prometheus, but for logs.
ko-build/setup-ko
step-security/set-github-variable
Use this Github Action to update a variable in your Github Action Workflows for your repository. Secure drop-in replacement for mmoyaferrer/set-github-variable.
cisagov/action-lineage
grafana/prometheus/.github/promci/actions/publish_main
The Prometheus monitoring system and time series database.
bats-core/bats-action
Github action that setup Bats and all the bats libs: support, assert, detik, file.
microsoft/powerplatform-actions/who-am-i
Power Platform GitHub Actions automate common build and deployment tasks related to Power Platform. This includes synchronization of solution metadata (a.k.a. solutions) between development environments and source control, generating build artifacts, deploying to downstream environments, provisioning/de-provisioning of environments, and the ability to perform static analysis checks against your solution using the PowerApps checker service.
step-security/actions-oidc-debugger/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
An Action for printing OIDC claims in GitHub Actions. Secure drop-in replacement for github/actions-oidc-debugger.
neondatabase/neon/.github/actions/run-python-test-set
Neon: Serverless Postgres. We separated storage and compute to offer autoscaling, code-like database branching, and scale to zero.