Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
dargon789/coinbase-smartcontracts/.github/actions/setup-env
Coinbase Developer ethereum smartcontracts deploy dapp hardhat foundry wagmi remix-project & tenderly verify contract uniswap 1inch defi dex onchain
yonasbsd/session-desktop/actions/make_release_build
Session Desktop - A Decentralized, Onion Routed, Private Messenger
codecov/test-results-action
federacy/scan-action
Github Action for security scanning utilizing Salus by Coinbase
anchore/go-make/.github/actions/wait-for-check
step-security/setup-yq
Sets up YQ, yet-another-markup-language-query-er, for use in your Github Actions workflow. Secure drop-in replacement for chrisdickinson/setup-yq.
paddlehq/go-aws-ssm/.github/actions/setup-databases
Wraps the aws-sdk-go and hides the complexity of dealing with the not so Go friendly AWS SDK.
envoyproxy/toolshed/actions/github/merge-commit
launchdarkly/js-eventsource/.github/actions/publish
EventSource client for Node.js and Browser (polyfill)
grafana/plugin-ci-workflows/actions/internal/plugins/package
Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins
step-security/allcheckspassed
GitHub Action to confirm that all checks reported on a commit have passed. Secure drop-in replacement for wechuli/allcheckspassed.
regclient/actions/image
actions-security-demo/script-injection/.grafana-main/pkg/build/actions/bump-version
grafana/grafana/.github/actions/setup-grafana-bench
The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
orhun/image
Encoding and decoding images in Rust
reality2byte/action/upload-sarif
koki-develop/hub-purge-action
๐งน Action to clear GitHub image caches.
appthreat/sast-scan-action
GitHub action for performing SAST scanning using various oss tools such as gitleaks, bandit, findsecbugs etc
step-security/terraform-cloud-provider-publish/__builder_checkout_dir__/.github/actions/secure-download-artifact
An action for publishing terraform providers to a private registry. Secure drop-in replacement for thechrisjohnson/terraform-cloud-provider-publish.
nvidia/nautobot-app-nvdatamodels/.github/.tmp/.generated-actions/run-pypi-publish-in-docker-container
A Nautobot plugin which provides data models for NVIDIA products