Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
yonasBSD/mise/.github/actions/fetch-token
dev tools, env vars, task runner
anysphere/docker-cache
Cache Docker Images Whether Built or Pulled
step-security/gh-actions-lua/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check
GitHub action for Lua/LuaJIT. Secure drop-in replacement for leafo/gh-actions-lua.
step-security/test-reporting/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Displays test results from popular testing frameworks directly in GitHub. Secure drop-in replacement for phoenix-actions/test-reporting.
authzed/action-spicedb-validate
GitHub Action for validating your SpiceDB schema
step-security/ghaction-github-runtime/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
GitHub Action to expose GitHub runtime to the workflow. Secure drop-in replacement for crazy-max/ghaction-github-runtime.
scottbrenner/cfn-lint-action
GitHub Action for interacting with CloudFormation Linter
SonarSource/sonarqube-scan-action/install-build-wrapper
caphyon/advinst-github-action
GitHub action for Advanced Installer tool
dataaxiom/ghcr-cleanup-action
GitHub Container Registry Cleanup Action
crazy-max/ghaction-upx
GitHub Action for UPX, the Ultimate Packer for eXecutables
wolfi-dev/actions/wolfictl-update-gh
A collection of reusable Github Actions workflows.
blinqas/tf-plan-pr-comment
blinqas/tf-plan-pr-comment
grafana/database-plugin-tools/.github/actions/check-labels
Create Grafana plugins with ease.
codecov/codecov-action
GitHub Action that uploads coverage to Codecov :open_umbrella:
uraimo/run-on-arch-action
A Github Action that executes jobs/commands on non-x86 cpu architectures (ARMv6, ARMv7, aarch64, s390x, ppc64le, riscv64) via QEMU
step-security/action-gh-release/__BUILDER_CHECKOUT_DIR__/.github/actions/compute-sha256
GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.
step-security/cirruslabs-cache/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact
Cache dependencies and build outputs in GitHub Actions. Secure drop-in replacement for cirruslabs/cache.