Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
akjus/bicep-registry-modules/.github/actions/templates/avm-setenvironment
Bicep registry modules
yonasbsd/syncstorage-rs/.github/actions/setup-python
Sync Storage server in Rust
qadottech/run-action/change-review
yonasbsd/ribir/.github/actions/image
Non-intrusive GUI framework for Rust/WASM
ledgerhq/ledger-live/tools/actions/composites/bot
Mono-repository for Ledger Wallet apps and related packages
matomo-org/github-action-checklist-gate
rapidsai/rmm/shared-actions/telemetry-impls/github-actions-job-info
NVIDIA RMM is a library for allocating and managing GPU memory in C++ and Python.
step-security/retry/__builder_checkout_dir__/.github/actions/privacy-check
Retries a GitHub Action step on failure or timeout. Secure drop-in replacement for nick-fields/retry.
envoyproxy/toolshed/actions/github/artifact/cache/save
step-security/zingdevlimited-actions-helpers
Collection of composite actions, callable workflows, and deployment scripts used for common Twilio deployment tasks. Secure drop-in replacement for zingdevlimited/actions-helpers.
step-security/sonarqube-scan-action/sidebar.tsx
Secure drop-in replacement for sonarsource/sonarqube-scan-action.
nautechsystems/nautilus_trader/.github/actions/attest-build-provenance-retry
Production-grade Rust-native trading engine with deterministic event-driven architecture
endorlabs/github-action
A GitHub action you can use to scan with Endor Labs
step-security/ssh-agent/__builder_checkout_dir__/.github/actions/privacy-check
GitHub Action to setup `ssh-agent` with a private key. Secure drop-in replacement for webfactory/ssh-agent.
grafana/shared-workflows/actions/validate-zizmor-config
A public-facing, centralized place to store reusable workflows used by Grafana Labs.
warpbuilds/cache/restore
Cache dependencies and build outputs in GitHub Actions
ministryofjustice/hmpps-github-actions-runner-security/.github/actions/docker-build
A special version of the Github Actions Runner specifically to run OWASP security scans (bootstrapped 2025-08-18)
redhat-actions/common/action-io-generator
Repository for shared config files, actions and planning.
step-security/checkov-action
This GitHub Action runs Checkov against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues. Secure drop-in replacement for bridgecrewio/checkov-action.
dustin4444/slsa-github-generator/.github/actions/secure-upload-folder
Language-agnostic SLSA provenance generation for Github Actions