Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
sonarsource/sonar-compliance-reports/.actions/get-build-number
Holds code for generating compliance reports
caffeelake/cilium/.github/actions/setup-eks-nodegroup
eBPF-based Networking, Security, and Observability
step-security/s3-actions-cache
Cache to S3 storage with official actions/cache@v2 fallback. Secure drop-in replacement for tespkg/actions-cache.
equinor/farfetched-actions/fusion-deploy
Reusable GitHub Actions and Workflows
rapidsai/shared-actions/trigger-workflow-and-wait
homebrew/actions/limit-pull-requests
๐ Homebrew's GitHub Actions
self-actuated/hub-mirror
GitHub Action to configure a Docker Hub mirror
nvidia-nemo/emerging-optimizers/.github/actions/test-template
step-security/cirruslabs-cache
Cache dependencies and build outputs in GitHub Actions. Secure drop-in replacement for cirruslabs/cache.
step-security/sbom-action/download-syft
GitHub Action for creating software bill of materials using Syft. Secure drop-in replacement for anchore/sbom-action.
ai-dynamo/dynamo/.github/actions/pytest-local
A Datacenter Scale Distributed Inference Serving Framework
mikepenz/action-junit-report
Reports junit test results as GitHub Pull Request Check
h2o-gpt/spring-boot/.github/actions/print-jvm-thread-dumps
Spring Boot helps you to create Spring-powered, production-grade applications and services with absolute minimum fuss.
elastic/oblt-actions/test-report
label305/autorebase
A GitHub Action that automatically rebases pull requests.
caffeelake/claude-code/.github/actions/claude-issue-triage-action
Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
laingcc/json-to-variables
GitHub action reads JSON file and writes its content as environment variables.
coveo/ui-kit/.github/actions/playwright-headless-search-react
Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.
caffeelake/llvm-project/.github/workflows/unprivileged-download-artifact
The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.
lewagon/wait-on-check-action
Pause until a job in another workflow completes successfully.