Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
bats-core/bats-action
Github action that setup Bats and all the bats libs: support, assert, detik, file.
optum/booster/.github/actions/public-layout.tsx
Booster Cloud Framework
microsoft/powerplatform-actions/who-am-i
Power Platform GitHub Actions automate common build and deployment tasks related to Power Platform. This includes synchronization of solution metadata (a.k.a. solutions) between development environments and source control, generating build artifacts, deploying to downstream environments, provisioning/de-provisioning of environments, and the ability to perform static analysis checks against your solution using the PowerApps checker service.
duplocloud/actions
Shared Github Actions for common situations.
neondatabase/neon/.github/actions/run-python-test-set
Neon: Serverless Postgres. We separated storage and compute to offer autoscaling, code-like database branching, and scale to zero.
wyrihaximus/github-action-next-semvers
Github Action that output the next version for major, minor, and patch version based on the given semver version.
launchdarkly/php-server-sdk-redis-predis/.github/actions/ci
Redis integration for the LaunchDarkly SDK for Server-side PHP using predis
launchdarkly/openfeature-python-server/.github/actions/build-docs
An OpenFeature provider for the LaunchDarkly Python server SDK.
optum/booster/.github/actions/call-rush
Booster Cloud Framework
step-security/auto-unapprove/__builder_checkout_dir__/.github/actions/secure-download-artifact
Secure drop-in replacement for RotemK1/auto-unapprove.
thomaseizinger/assign-pr-creator-action
step-security/multi-labeler/__builder_checkout_dir__/.github/actions/privacy-check
Multi labeler for title, body, comments, commit messages, branch, author or files with automated status checks. Secure drop-in replacement for fuxingloh/multi-labeler.
scalr/scalr-action
Scalr Github Action
simonmarty/aws-secretsmanager-get-secrets/.github/actions/build
rust-build/rust-build.action
Automate publishing Rust build artifacts for GitHub releases through GitHub Actions
viasat::Git-Viasat-Com-PoC::seceng-vionix-stepsecurity-poc-test/viarise/benchmark-dockerfile
istio/get-istioctl
ashishkurmi/changed-files
cardinalby/git-tag-action
GitHub action that adds a git tag to the current workflow commit
asymmetric-research/clusterfuzz-fuzzbot-builder/_next/image/assets/brand/step-security-brand-name.svg
Build environment matching a FuzzBot running Ubuntu 22.04