Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
qte77/gha-sbom-action
Composite GitHub Action that generates SPDX SBOM files using the GitHub dependency graph API and Syft, optionally opening a pull request with the results.
ljharb/actions/node/pack
GitHub actions I use for CI.
step-security/action-tflint
Run tflint with reviewdog on pull requests to enforce best practices. Secure drop-in replacement for reviewdog/action-tflint.
yepcode/gha-copy-team
GitHub Action that copies all the contents from the current git repository to one YepCode remote team.
slsa-framework/slsa-github-generator/.github/actions/detect-workflow
Language-agnostic SLSA provenance generation for Github Actions
mxcl/xcodebuild
A continuously resilient `xcodebuild` βGitHub Actionβ. Also itβs the best.
netlify/actions/cli
octodemo-resources/github-url-resolver-action
GitHub Action to resolve URLs that are associated with a specific GitHub instance
dagster-io/dagster-cloud-action/actions/utils/prerun
natiginfo/action-detekt-all
Run Detekt static analysis in GitHub Actions with configurable Detekt and Java versions.
nvidia/nvmath-python/.github/actions/get_pr_number
NVIDIA Math Libraries for the Python Ecosystem
step-security/install-poetry/__builder_checkout_dir__/.github/actions/secure-download-artifact
Github action for installing and configuring Poetry. Secure drop-in replacement for snok/install-poetry.
step-security/setup-protoc/__builder_checkout_dir__/.github/actions/secure-download-artifact
GitHub Action to setup the protoc compiler for protocol buffers. Secure drop-in replacement for arduino/setup-protoc.
grafana/setup-k6-action
GitHub Action for installing Grafana k6
kong/gh-storage/download
Use a GitHub hosted repository to store and retrieve files
bridgecrewio/yor-action
Github action for Yor
coveord/spinnaker/.github/actions/build-tag-number
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence.
anchore/chronicle/.github/actions/wait-for-check
a fast changelog generator sourced from PRs and Issues
zwaldowski/semver-release-action
Create the next semantic version and tag it.
matmair/inventree/.github/actions/setup
Open Source Inventory Management System