Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
hynek/build-and-inspect-python-package
Build and Inspect Python Packages in GitHub Actions
step-security/setup-uv/__builder_checkout_dir__/.github/actions/secure-download-artifact
Set up your GitHub Actions workflow with a specific version of https://docs.astral.sh/uv/. Secure drop-in replacement for astral-sh/setup-uv.
actions-tools/yaml-outputs
GitHub Action to read a YAML file and flatten it recursively into outputs
palewire/internet-archive-upload
Upload files to an archive.org collection in your GitHub Action
coveord/spinnaker/.github/actions/spinnaker-release
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence.
iancha1992/continuous-integration/actions/cherry_picker
Bazel's Continuous Integration Setup
metamask/security-code-scanner
A GitHub action aggregating SAST tools to scan code for vulnerabilities
nvidia/openshell/.github/actions/setup-buildx
OpenShell is the safe, private runtime for autonomous AI agents.
gitleaks/gitleaks-action
Protect your secrets using Gitleaks-Action
zimperium/zscanmarketplace
tecolicom/actions-use-apt-tools
Github action for apt packages
yonasbsd/surrealdb/.github/actions/publish-binaries
A scalable, distributed, collaborative, document-graph database, for the realtime web
step-security/changed-files
Github action to retrieve all (added, copied, modified, deleted, renamed, type changed, unmerged, unknown) files and directories. Secure drop-in replacement for tj-actions/changed-files.
joshuathemiller/conditional-build-matrix
A GitHub Action that enables easier conditional matrix builds!
slsa-framework/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact
Language-agnostic SLSA provenance generation for Github Actions
politicalsphere/ci/.github/actions/consumer-contract
CI/CD pipelines and GitHub Actions for Political Sphere
grafana/mimir-loki/lib/actions/push-images
Like Prometheus, but for logs.
nvidia/aicr/.github/actions/aicr-build
Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes
warchant/setup-sonar-scanner
Github Action which downloads and runs sonar-scanner cli with custom parameters to start Sonarqube scan.
dudinea/argo-cd/__builder_checkout_dir__/.github/actions/privacy-check
Declarative Continuous Deployment for Kubernetes