Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/sticky-pull-request-comment/__builder_checkout_dir__/.github/actions/secure-download-artifact
Create comment on pull request, if exists update that comment. Secure drop-in replacement for marocchino/sticky-pull-request-comment.
n80fr1n60/secure-checkout
Drop-in replacement for actions/checkout@vX.Y.Z with persist-credentials=false enforced
kong/developer.konghq.com/.github/reusable-steps/run-site
๐ฆ Source code for developer.konghq.com website.
lfreleng-actions/maven-make-build-action
Uses a Makefile to build a Maven project
nodoubtz-record-label/next.js/.github/actions/upload-turboyet-data
The React Framework
smartcontractkit/.github/actions/ctf-cleanup
reusable GHA workflows and actions
slsa-framework/slsa-github-generator/__builder_checkout_dir__/.github/actions/compute-sha256
Language-agnostic SLSA provenance generation for Github Actions
manticoresoftware/publish_to_repo
Action to publish packages to Manticore repo
release-drafter/release-drafter/docker
Drafts your next release notes as pull requests are merged into master.
aerospike/spring-data-aerospike-starters/.github/actions/stage-release-artifacts
spring-data-aerospike-starters
sakhnovict/add-reviewers-action
GitHub Action to add reviewer(s) to a pull request.
redhat-actions/oc-new-app
Github Action to deploy and expose an application on Openshift
oasdiff/oasdiff-action/breaking
GitHub action for comparing and detect breaking changes in OpenAPI specs
jordanconway/package-manager-hardening
A non-exhaustive list of package manager hardening recommendations to help prevent supply chain vulnerability attacks. Includes AGENTS.md files, skills and Github Action to audit and enforce these recommendations.
garygrossgarten/github-action-scp
โฌ๏ธ Copy a folder to a remote server using SSH
august-murr/auto-labeler
git-hub-chris/visualstudiocode/actions/needs-more-info-closer
Microsoft Visual Studio Code.
caffeelake/cilium/.github/actions/setup-eks-cluster
eBPF-based Networking, Security, and Observability
yonasbsd/sanity/.github/actions/setup
Sanity Studio โ Rapidly configure content workspaces powered by structured content
step-security/read-yaml/__builder_checkout_dir__/.github/actions/privacy-check
A GitHub Action to read yaml files. Secure drop-in replacement for jbutcher5/read-yaml.