Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

tomhjp/gh-action-jira-create

tomhjp/gh-action-jira-create

GitHub action to create Jira tickets with customisable fields

3/10
phips28/gh-action-bump-version

phips28/gh-action-bump-version

GitHub Action for automated npm version bump.

3/10
JoftheV/pytorch/.github/actions/teardown-xpu

JoftheV/pytorch/.github/actions/teardown-xpu

Tensors and Dynamic neural networks in Python with strong GPU acceleration

3/10
deepcode-ai/codeql/ql/.github/actions/fetch-codeql

deepcode-ai/codeql/ql/.github/actions/fetch-codeql

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

2/10
LoliGothick/rustfmt-check

LoliGothick/rustfmt-check

GitHub Action for PR annotations with rustfmt checks

5/10
approved-3rd-party-actions/commit-message-checker

approved-3rd-party-actions/commit-message-checker

GitHub Action that checks commit messages of pushes and pull request against a regex pattern

2/10
NVIDIA/JAX-Toolbox/.github/actions/submit-delete-k8s-job

NVIDIA/JAX-Toolbox/.github/actions/submit-delete-k8s-job

JAX-Toolbox

6/10
grafana/grafana/.github/actions/changelog

grafana/grafana/.github/actions/changelog

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

6/10
a11smiles/GitSync

a11smiles/GitSync

A workflow action that syncs GitHub and Azure DevOps activities.

2/10
hadolint/hadolint-action

hadolint/hadolint-action

GitHub action for Hadolint, A Dockerfile linting tool

7/10
aks-lts/test-infra

aks-lts/test-infra

LTS specific configuration and tooling for testing

3/10
hashicorp/sentinel-github-actions

hashicorp/sentinel-github-actions

5/10
slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact

slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact

Language-agnostic SLSA provenance generation for Github Actions

5/10
step-security/ghaction-github-runtime/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/ghaction-github-runtime/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

GitHub Action to expose GitHub runtime to the workflow. Secure drop-in replacement for crazy-max/ghaction-github-runtime.

10/10
rjdbcm/ozi-publish

rjdbcm/ozi-publish

OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release

7/10
masci/datadog

masci/datadog

Send Datadog metrics, events, service checks and logs from GitHub workflows

3/10
pytorch/text/test-infra/.github/actions/chown-directory

pytorch/text/test-infra/.github/actions/chown-directory

Models, data loaders and abstractions for language processing, powered by PyTorch

2/10
NVIDIA/cudaqx/.github/actions/get-cudaq-build

NVIDIA/cudaqx/.github/actions/get-cudaq-build

Accelerated libraries for quantum-classical computing built on CUDA-Q.

6/10
angular/dev-infra/github-actions/bazel/configure-remote

angular/dev-infra/github-actions/bazel/configure-remote

Angular Development Infrastructure

6/10
envoyproxy/toolshed/gh-actions/jq

envoyproxy/toolshed/gh-actions/jq

6/10