Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
hashicorp/tfc-workflows-github/actions/apply-run
HCP Terraform starter workflows and github actions to automate Terraform Cloud CI/CD pipelines.
step-security/release-downloader
Github action to download release assets from private or public repositories. Secure drop-in replacement for robinraju/release-downloader.
launchdarkly/gha-ld-gosec
Runs gosec then uploads results to s3 and workflow artifacts.
step-security/action-openfga-test
Github Action for testing your OpenFGA Authorization Model. Secure drop-in replacement for openfga/action-openfga-test.
meilcli/gradle-update-check-action
gradle maven new package version check action for GitHub Actions.
richardmcsong/actions/pr-sync
Custom actions for automating Backstage workflows
githubnext/gh-aw/actions/setup
GitHub Agentic Workflows
quotidian-ennui/actions-olio/commit-status-and-label
It's a gallimaufry of actions
ministryofjustice/hmpps-probation-integration-services/.github/actions/database-access-new
A collection of small, domain-focused integrations to support HMPPS Digital services that need to interact with probation data.
nvidia/nvsentinel/.github/actions/install-e2e-tools
NVSentinel is a cross-platform fault remediation service designed to rapidly remediate runtime node-level issues in GPU-accelerated computing environments
tue-robotics/tue-env/ci/fill
Package manager that can be used to install (ROS) dependencies
docker/bake-action/ui13c5/list-targets
GitHub Action to use Docker Buildx Bake as a high-level build command
microsoft/setup-kiota
Action that installs Kiota OpenAPI client generator so it can be used in your workflow
easingthemes/ssh-deploy
GitHub Action for deploying code via rsync over ssh. (with NodeJS)
grafana/community-contributions/.github/actions/check-jobs
External contributor PR workflow testing sandbox
rvben/rumdl
Fast Markdown linter and formatter written in Rust
architect/action-build
aerospike/aerospike-client-java/.github/actions/build-and-test
Aerospike Java Client Library
step-security/npm-get-version-action
This Action scans for a package.json file and reads the version number from that. Secure drop-in replacement for martinbeentjes/npm-get-version-action.