Assess the risk of third-party GitHub Actions
Examples: ,
Actions
Assess all the actions
step-security/protobuf-ci/__builder_checkout_dir__/.github/actions/public-layout.tsx
A shared repository for Protobuf CI actions. Secure drop-in replacement for protocolbuffers/protobuf-ci.
aerospike/aerospike-client-java/.github/actions/publish-build-info-to-jfrog
Aerospike Java Client Library
cybrking/thr8
Automatically generate PASTA threat models from your repo using Claude AI.
redpanda-data/redpanda/ghca/actions/slash-command-error
Redpanda is a streaming data platform for developers. Kafka API compatible. 10x faster. No ZooKeeper. No JVM!
redpanda-data/llvm-project/.github/workflows/get-llvm-version
The LLVM Project is a collection of modular and reusable compiler and toolchain technologies. Note: the repository does not accept github pull requests at this moment. Please submit your patches at http://reviews.llvm.org.
hiddenlayerai/hiddenlayer-model-scan-github-action
Official HiddenLayer Github Action for the Model Scanner
palewire/install-python-pipenv-pipfile
Easily install Python, pipenv and Pipfile packages in your GitHub Action
step-security/action-install-gh-release
GitHub Action to install the Github Release binaries. Secure drop-in replacement for jaxxstorm/action-install-gh-release.
ministryofjustice/laa-manage-your-civil-cases/.github/actions/deploy
A service to centrally manage civil legal aid cases for the Legal Aid Agency
rudderlabs/kata-containers/.github/cargo-deny-composite-action
Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/
actionutils/create-release-pr
WIP
prateek-stepsecurity/harden-runner
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
mitchellh/vouch/action/check-pr
A community trust management system based on explicit vouches to participate.
karancode/yamllint-github-action
Github Action for linting yaml files using yamllint
step-security/setup-xcode
Set up your GitHub Actions workflow with a specific version of Xcode. Secure drop-in replacement for maxim-lobanov/setup-xcode.
pytorch/tensordict/test-infra/.github/actions/teardown-windows
TensorDict is a pytorch dedicated tensor container.
casadi/commercial_solvers
Set up commercial solvers in CI for testing purposes
asottile/workflows/.github/actions/fast-checkout
reusable github workflows / actions
sredevopsorg/kserve/.github/actions/kserve-dep-setup
Standardized Serverless ML Inference Platform on Kubernetes
kong/proxy-wasm-rust-response-transformer/.github/actions/setup
Response Transformer WASM Filter written in Rust