Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
divd-nl/cna-bot
GitHub action to validate and submit CVE entries using cvelib, cvelint and cve service.
treosh/lighthouse-ci-action
Audit URLs using Lighthouse and test performance with Lighthouse CI.
contosoenterprise/variable-substitution
Enable GitHub developers to parameterize the values in their config files from a GitHub Action workflow
scribe-security/action-bom
Github action to Collect, Create and Store SBOM evidence
smartcontractkit/.github/actions/get-pr-labels
reusable GHA workflows and actions
step-security/openapitools-generator-action
Generate a client library using the OpenAPITools Generator. Secure drop-in replacement for openapi-generators/openapitools-generator-action.
jfheinrich-eu/psono-secret-whisperer
A GitHub Action for securely retrieving secrets from PSONO server
step-security/upload-release-action
Upload files to a GitHub release. Secure drop-in replacement for svenstaro/upload-release-action.
cycjimmy/semantic-release-action
GitHub Action for Semantic Release
openzeppelin/openzeppelin-contracts/.github/actions/setup
OpenZeppelin Contracts is a library for secure smart contract development.
gittools/actions
GitHub Action that installs and uses the GitVersion and GitReleaseManager tools
w3c/spec-prod
GitHub Action to build ReSpec/Bikeshed specs, validate output and publish to GitHub pages or W3C
tyriis/docker-image-tag-exists
GitHub Action to check if a docker container image exists in a registry.
saschanowak/clovercodecoveragesummary
A GitHub Action that reads Clover format code coverage files from your test suite and outputs a markdown summary
christian-draeger/increment-semantic-version
stoplightio/spectral-action
GitHub Action wrapper for Spectral - a JSON/YAML/OpenAPI/AsyncAPI/etc linter with custom rule support.
google/osv-scanner-action/osv-reporter-action
briansmith/codecov-codecov-action
GitHub Action that uploads coverage to Codecov :open_umbrella:
appleboy/lambda-action
GitHub Action for Deploying Lambda code to an existing function
surrealdb/rocksdb/.github/actions/setup-upstream
A library that provides an embeddable, persistent key-value store for fast storage.