Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
useblacksmith/cache-delete
jessehouwing/actions-dependency-submission
Action to automatically report versions for pinned action dependencies
deef0000dragon1/json-edit-action
Github Action to make a change to a JSON file
step-security/r-lib-actions/setup-pandoc
GitHub Actions for the R community. Secure drop-in replacement for r-lib/actions.
step-security/gitleaks-action
Protect your secrets using Gitleaks-Action. Secure drop-in replacement for gitleaks/gitleaks-action.
devantler-tech/ksail/.github/actions/npm-audit-and-fix
All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.
rigs-it/xanitizer-action
GitHub action to download and install Xanitizer, and to run a Xanitizer security analysis in a GitHub workflow.
sasobadovinac/pytorch/.github/actions/diskspace-cleanup
Tensors and Dynamic neural networks in Python with strong GPU acceleration
step-security/create-or-update-comment
A GitHub action to create or update an issue or pull request comment. Secure drop-in replacement for peter-evans/create-or-update-comment.
slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml
Language-agnostic SLSA provenance generation for Github Actions
pytorch/vision/test-infra/.github/actions/calculate-docker-image
Datasets, Transforms and Models specific to Computer Vision
harden-runner-canary/docker-action-k8s
pytorch/tensordict/test-infra/.github/actions/teardown-linux
TensorDict is a pytorch dedicated tensor container.
dargon789/node/.github/actions/install-clang
Node.js JavaScript runtime โจ๐ข๐โจ
grafana/falconlogscale-datasource/actions/public-layout.tsx
Falcon LogScale data source for Grafana
actions-security-demo/script-injection/.github/actions/setup-enterprise
loft-sh/image
Work with containers' images
grafana/tns/_shared-workflows-dockerhub-login/actions/get-vault-secrets
Observability Demo App
eclipse-dash/dash-licenses/.github/actions/fill
Extract license information from content.
pypa/gh-action-pypi-publish
The blessed :octocat: GitHub Action, for publishing your :package: distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish