Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

pytorch/ao/test-infra/.github/actions/chown-directory

pytorch/ao/test-infra/.github/actions/chown-directory

PyTorch native quantization and sparsity for training and inference

4/10
rudderlabs/build-scan-push-action

rudderlabs/build-scan-push-action

6/10
rossjrw/pr-preview-action

rossjrw/pr-preview-action

GitHub Action that deploys a pull request preview to GitHub Pages, similar to Vercel and Netlify, and cleans up after itself.

5/10
pytorch/test-infra/test-infra/.github/actions/set-channel

pytorch/test-infra/test-infra/.github/actions/set-channel

This repository hosts code that supports the testing infrastructure for the PyTorch organization. For example, this repo hosts the logic to track disabled tests and slow tests, as well as our continuation integration jobs HUD/dashboard.

4/10
pytorch/torchcodec/test-infra/.github/actions/pull-docker-image

pytorch/torchcodec/test-infra/.github/actions/pull-docker-image

PyTorch media decoding and encoding

4/10
PaddleHQ/repo-file-sync-action

PaddleHQ/repo-file-sync-action

🔄 GitHub Action to keep files like Action workflows or entire directories in sync between multiple repositories.

4/10
mondeja/remove-labels-gh-action

mondeja/remove-labels-gh-action

Remove labels from GitHub issues or pull requests

2/10
step-security/release-notes-generator-action

step-security/release-notes-generator-action

Action to auto generate a release note based on your events. Secure drop-in replacement for Decathlon/release-notes-generator-action.

10/10
Maintained by StepSecurity
haythem/public-ip

haythem/public-ip

Queries GitHub actions runner's public IP address

5/10
kunalnagarco/action-cve

kunalnagarco/action-cve

A GitHub action that sends Dependabot Vulnerability Alerts to multiple sources.

3/10
bus1/cabuild/action/msdevshell

bus1/cabuild/action/msdevshell

Content-Addressable Build Environments

2/10
oxsecurity/megalinter/flavors/cupcake

oxsecurity/megalinter/flavors/cupcake

🦙 MegaLinter analyzes 50 languages, 22 formats, 21 tooling formats, excessive copy-pastes, spelling mistakes and security issues in your repository sources with a GitHub Action, other CI tools or locally.

7/10
soos-io/soos-dast-github-action

soos-io/soos-dast-github-action

SOOS DAST GitHub Action - Register for a Free Trial at https://app.soos.io/register

4/10
snnaplab/get-labels-action

snnaplab/get-labels-action

3/10
optum/sourcehawk/.github/actions/build-windows-native-image

optum/sourcehawk/.github/actions/build-windows-native-image

Sourcehawk is an extensible compliance as code tool which allows development teams to run compliance scans on their source code.

3/10
singularityhub/install-singularity

singularityhub/install-singularity

Action to install Singlarity optimized for simplicity.

3/10
step-security/filter-sarif

step-security/filter-sarif

GitHub Action for filtering Code Scanning alerts by path and id. Secure drop-in replacement for advanced-security/filter-sarif.

10/10
Maintained by StepSecurity
step-security/gh-find-current-pr/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/gh-find-current-pr/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Github Action for finding the Pull Request (PR) associated with the current SHA. Secure drop-in replacement for jwalton/gh-find-current-pr.

10/10
aliyun/ack-set-context

aliyun/ack-set-context

3/10
GrantBirki/git-diff-action

GrantBirki/git-diff-action

A GitHub Action for gathering the git diff of a pull request in raw or JSON format

4/10