Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

harden-runner-canary/kyverno/.github/actions/is-defined

harden-runner-canary/kyverno/.github/actions/is-defined

Kubernetes Native Policy Management

3/10
heisenberg-2077/use-npm-token-action

heisenberg-2077/use-npm-token-action

Use an NPM token within an .npmrc file inside GitHub actions. Scoped packages are the primary use case.

2/10
tjenkinson/gh-action-auto-merge-dependency-updates

tjenkinson/gh-action-auto-merge-dependency-updates

A GitHub action that will automatically approve and merge a PR that only contains dependency updates, based on some rules. Also possible to disable the merge and use the `success` output to use in combination with other actions.

2/10
Reality2byte/setup-python

Reality2byte/setup-python

Set up your GitHub Actions workflow with a specific version of Python

4/10
grafana/sqlds/actions/commands

grafana/sqlds/actions/commands

A package that assists writing SQL-driven datasources

7/10
pytorch/torchtitan/test-infra/.github/actions/setup-ssh

pytorch/torchtitan/test-infra/.github/actions/setup-ssh

A PyTorch native platform for training generative AI models

6/10
open-policy-agent/setup-regal

open-policy-agent/setup-regal

Run Regal, the OPA Rego Linter, as a GitHub Action

3/10
siemens/ix/.github/workflows/actions/storybook

siemens/ix/.github/workflows/actions/storybook

Siemens Industrial Experience is a design system for designers and developers, to consistently create the perfect digital experience for industrial software products.

6/10
actions-ecosystem/action-bump-semver

actions-ecosystem/action-bump-semver

⏫ GitHub Action to bump the semver version up

3/10
juliangruber/merge-pull-request-action

juliangruber/merge-pull-request-action

A simple GitHub Action for merging pull requests

1/10
sredevopsorg/nhost/.github/actions/install-dependencies

sredevopsorg/nhost/.github/actions/install-dependencies

The Open Source Firebase Alternative with GraphQL.

3/10
step-security/rust-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/rust-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

A GitHub Action that implements smart caching for rust/cargo projects. Secure drop-in replacement for Swatinem/rust-cache.

10/10
hugoheml/update_release

hugoheml/update_release

This GitHub Action (written in JavaScript) is to change the Body Text and Name of an already created Release with using the GitHub Release API.

2/10
grafana/mimir-loki/actions/metrics-collector

grafana/mimir-loki/actions/metrics-collector

Like Prometheus, but for logs.

3/10
AndreMiras/coveralls-python-action

AndreMiras/coveralls-python-action

GitHub Action for Python Coveralls.io

4/10
step-security/setup-bun/.github/actions/compare-bun-version

step-security/setup-bun/.github/actions/compare-bun-version

Set up your GitHub Actions workflow with a specific version of Bun. Secure drop-in replacement for oven-sh/setup-bun.

10/10
step-security/release-notes-generator-action/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

step-security/release-notes-generator-action/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256

Action to auto generate a release note based on your events. Secure drop-in replacement for Decathlon/release-notes-generator-action.

10/10
ZedThree/clang-tidy-review/upload

ZedThree/clang-tidy-review/upload

Create a pull request review based on clang-tidy warnings

5/10
elastic/oblt-actions/pre-commit

elastic/oblt-actions/pre-commit

7/10
lost-pixel/lost-pixel

lost-pixel/lost-pixel

Open source alternative to Percy, Chromatic, Applitools.

3/10