Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

appleboy/scp-action

appleboy/scp-action

GitHub Action that copy files and artifacts via SSH.

5/10
ad-m/github-push-action

ad-m/github-push-action

GitHub actions to push back to repository eg. updated code

5/10
alexellis/upload-assets

alexellis/upload-assets

GitHub Action to upload multiple assets to a release

4/10
actions-security-demo/script-injection/pkg/build/actions/bump-version

actions-security-demo/script-injection/pkg/build/actions/bump-version

2/10
Maggi64/eslint-plus-action

Maggi64/eslint-plus-action

ESLint via Github Actions on changed files with annotations & comments

2/10
coinbase/cdp-sdk/.github/actions/fetch-docs-artifact

coinbase/cdp-sdk/.github/actions/fetch-docs-artifact

Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys.

6/10
zaproxy/action-full-scan

zaproxy/action-full-scan

A GitHub Action for running the ZAP Full scan

7/10
oracle-actions/setup-java

oracle-actions/setup-java

GitHub Action to download and install Oracle's Java Development Kit builds

8/10
actions-rs/toolchain

actions-rs/toolchain

🛠️ GitHub Action for `rustup` commands

3/10
lfreleng-actions/gerrit-clone-action

lfreleng-actions/gerrit-clone-action

Action to bulk clone (in parallel) an entire Gerrit server repository hierarchy

4/10
asyncapi/.github/.github/actions/get-node-version-from-package-lock

asyncapi/.github/.github/actions/get-node-version-from-package-lock

Location of all reusable community health files

8/10
proyecto-chaucha/chaucha-gha-wallet-generator

proyecto-chaucha/chaucha-gha-wallet-generator

Chaucha functions for usage with Github Actions

3/10
Reality2byte/action/.github/actions/setup-swift

Reality2byte/action/.github/actions/setup-swift

3/10
coinbase/cds/.github/actions/setup

coinbase/cds/.github/actions/setup

Coinbase Design System

6/10
aerospike/aerospike-client-python/.github/actions/setup-docker-on-macos

aerospike/aerospike-client-python/.github/actions/setup-docker-on-macos

Aerospike Python Client

4/10
ministryofjustice/action-clean-runner

ministryofjustice/action-clean-runner

Composite action for freeing up space on GitHub-hosted runner

6/10
scientific-python/circleci-artifacts-redirector-action

scientific-python/circleci-artifacts-redirector-action

GitHub Action to add a GitHub status link to a CircleCI artifact.

6/10
anysphere/cache-apt-pkgs-action

anysphere/cache-apt-pkgs-action

Cache APT packages in GitHub Actions

5/10
machine-learning-apps/actions-app-token

machine-learning-apps/actions-app-token

Impersonate a GitHub App Token inside Actions

2/10
actions/dependency-review-action

actions/dependency-review-action

A GitHub Action for detecting vulnerable dependencies and invalid licenses in your PRs

9/10