Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/github-action-aerospike
GitHub Action to set up an Aerospike database. Secure drop-in replacement for reugn/github-action-aerospike.
pactflow/actions/fill
GitHub Actions to perform common Pact & Pactflow commands
coveo/plasma/.github/actions/deploy
Plasma components implemented with React!
step-security/sbom-action/image
GitHub Action for creating software bill of materials using Syft. Secure drop-in replacement for anchore/sbom-action.
advanced-security/codeql-development-toolkit/.github/actions/install-qlt
The CodeQL Development toolkit is a tool for making common CodeQL development workflows easier.
andife/openvino/.github/actions/smart-ci
OpenVINOβ’ is an open source toolkit for optimizing and deploying AI inference
jonasalfredsson/checkout-qemu-buildx
GitHub Action which checkout the repository and configures QEMU and Docker Builx for all available architectures.
philips-software/amp-devcontainer/.github/actions/container-size-diff
πamp-devcontainer is a batteries-included devcontainer useable for modern software development
step-security/dsanders11-project-actions/github-script
A collection of actions for automating GitHub projects. Secure drop-in replacement for dsanders11/project-actions.
grafana/grafana-cloudwatch-datasource/actions/commands
Grafana CloudWatch Datasource plugin
step-security/create-or-update-pull-request-action
A GitHub Action to create or update a pull request based on local changes. Secure drop-in replacement for gr2m/create-or-update-pull-request-action.
step-security/openapitools-generator-action/__builder_checkout_dir__/.github/actions/privacy-check
Generate a client library using the OpenAPITools Generator. Secure drop-in replacement for openapi-generators/openapitools-generator-action.
jonathancombs782/aspire/.github/actions/check-changed-files
Aspire is the tool for code-first, extensible, observable dev and deploy.
sredevopsorg/ghost-on-kubernetes/.github/actions/set-ghost-version
Ghost on Kubernetes by SREDevOps.org - Deploy Ghost v6 on Kubernetes (k8s, k3s, etc) with our hardened distroless rootless custom image.
anysphere/bugbot-context
cloudposse/github-action-yaml-config-query
Define YAML document, filter it with JSON query and get result as outputs
yonasbsd/buck2/.github/actions/build_debug
Build system, successor to Buck
gliech/create-github-secret-action
Github Action that can create or update secrets in the GitHub Actions API
yonasbsd/ghost/.github/actions/load-docker-image
Independent technology for modern publishing, memberships, subscriptions and newsletters.
devsectop/tf-via-pr
Plan and apply Terraform/OpenTofu via PR automation, using best practices for secure and scalable IaC workflows.