Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/gradle-actions/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
A collection of GitHub Actions to accelerate your Gradle Builds on GitHub. Secure drop-in replacement for gradle/actions.
step-security/r-lib-actions/setup-pandoc
GitHub Actions for the R community. Secure drop-in replacement for r-lib/actions.
step-security/create-or-update-comment
A GitHub action to create or update an issue or pull request comment. Secure drop-in replacement for peter-evans/create-or-update-comment.
slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml
Language-agnostic SLSA provenance generation for Github Actions
pytorch/vision/test-infra/.github/actions/calculate-docker-image
Datasets, Transforms and Models specific to Computer Vision
harden-runner-canary/docker-action-k8s
pytorch/tensordict/test-infra/.github/actions/teardown-linux
TensorDict is a pytorch dedicated tensor container.
actions-security-demo/script-injection/.github/actions/setup-enterprise
grafana/tns/_shared-workflows-dockerhub-login/actions/get-vault-secrets
Observability Demo App
pypa/gh-action-pypi-publish
The blessed :octocat: GitHub Action, for publishing your :package: distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish
shivammathur/cache-extensions
:package: Cache PHP extensions in GitHub Actions
step-security/background-action
Background commands with log tailing/capture; waits until file/port/socket/http are ready to proceed. Isolates/dedupe errors. Secure drop-in replacement for JarvusInnovations/background-action.
edera-dev/falco_plugin/.github/actions/install-llvm
A Falco plugin for forwarding low-level events (syscalls, etc) out of Edera zones.
step-security/jest-coverage-report-action
Track your code coverage in every pull request. Secure drop-in replacement for ArtiomTr/jest-coverage-report-action.
CordEngine/.github/actions/qa
step-security/auto-assign-issue/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
GitHub Action that auto-assigns issues or PRs to one or more users. Secure drop-in replacement for pozil/auto-assign-issue.
gofrolist/molecule-action
GitHub Action for running molecule as part of your workflows!
asdf-vm/actions/setup
GitHub Actions for the asdf version manager
ministryofjustice/hmpps-probation-integration-services/.github/actions/merge-changes
A collection of small, domain-focused integrations to support HMPPS Digital services that need to interact with probation data.