An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

github actions "devsecops" keyword

Top 1.0% on github actions
zaproxy/action-baseline v0.15.0 💰
Scans the web application with the ZAP Baseline Scan
18 versions - Latest release: 11 months ago - 497 dependent repositories - 369 stars on GitHub
Top 0.7% on github actions
trufflesecurity/trufflehog v3.97.0
Find and verify leaked credentials in your source code.
356 versions - Latest release: 22 days ago - 519 dependent repositories - 27,644 stars on GitHub
Top 1.3% on github actions
zaproxy/action-full-scan v0.13.0 💰
Scans the web application with the ZAP Full Scan
14 versions - Latest release: 11 months ago - 215 dependent repositories - 386 stars on GitHub
Top 7.5% on github actions
jetbrains/qodana-action v2026.2.0
Scan your projects with Qodana on GitHub. Docs: https://jb.gg/qodana-github-action
66 versions - Latest release: about 1 month ago - 307 stars on GitHub
Top 0.3% on github actions
aquasecurity/trivy-action v0.36.0
Scans container images for vulnerabilities with Trivy
151 versions - Latest release: 5 months ago - 3,327 dependent repositories - 1,394 stars on GitHub
Pwd9000-ML/azure-vm-password-rotate v1.1.0
Rotate AZURE virtual machines local administrator Passwords, using AZURE key vault
4 versions - Latest release: over 4 years ago - 1 dependent repositories - 3 stars on GitHub
Top 7.2% on github actions
GeekMasher/advanced-security-compliance v1.7.0
ghascompliance
13 versions - Latest release: over 3 years ago - 1 dependent repositories - 134 stars on GitHub
Top 1.9% on github actions
GitGuardian/ggshield-action v1.53.0
Scan commits for secrets and other issues.
57 versions - Latest release: about 1 month ago - 173 dependent repositories - 351 stars on GitHub
kubeshop/monokle-action v0.3.3
Monokle Action analyzes your Kubernetes resources to quickly find misconfigurations.
9 versions - Latest release: about 2 years ago - 1 dependent repositories - 5 stars on GitHub
reviewdog/action-trivy v1.15.0 💰
🐶 Run trivy with reviewdog on pull requests to enforce security best practices
65 versions - Latest release: 2 months ago - 17 stars on GitHub
Top 1.1% on github actions
JetBrains/qodana-action v2026.2.0
Scan your projects with Qodana on GitHub. Docs: https://jb.gg/qodana-github-action
66 versions - Latest release: about 1 month ago - 1,114 dependent repositories - 308 stars on GitHub
fabiocicerchia/gandalf v0.4.0 💰
Review a pull request with gandalf's scanners - inline comments, and findings ingested into GitHu...
7 versions - Latest release: 17 days ago - 0 stars on GitHub
Top 4.7% on github actions
pyupio/safety 3.12.13 💰
Runs the Safety CLI dependency scanner against your project
121 versions - Latest release: over 1 year ago - 3 dependent repositories - 1,995 stars on GitHub
Top 2.2% on github actions
bridgecrewio/bridgecrew-action v1.2343.0
Find and fix security and compliance issues in infrastructure as code, open source packages, cont...
1,100 versions - Latest release: almost 3 years ago - 114 dependent repositories - 71 stars on GitHub
Top 6.3% on github actions
nightfallai/nightfall_dlp_action v2.2.0
Scan Pull Requests for sensitive information, like credentials & secrets, PII, credit card number...
16 versions - Latest release: about 3 years ago - 4 dependent repositories - 58 stars on GitHub
Top 0.9% on github actions
bridgecrewio/checkov-action v12.3121.0
Run Checkov against infrastructure as code, open source packages, container images, and CI/CD con...
1,656 versions - Latest release: 10 days ago - 507 dependent repositories - 314 stars on GitHub
homeofe/supply-chain-guard v6.0.1
Scan your repository for supply-chain malware indicators. Detects GlassWorm and similar campaigns.
141 versions - Latest release: 12 days ago - 5 stars on GitHub
Top 6.7% on github actions
fike/horusec-action v0.2.2
Run Horusec SAST in your code
7 versions - Latest release: about 4 years ago - 17 dependent repositories - 13 stars on GitHub
GitGuardian/ggshield v1.54.0
Scan commits for security incidents (using repository image)
107 versions - Latest release: 10 days ago - 1,985 stars on GitHub
Top 3.2% on github actions
tonybaloney/pycharm-security 1.29.0 💰
Scan your Python Code for security issues
51 versions - Latest release: about 3 years ago - 23 dependent repositories - 350 stars on GitHub
Top 4.7% on github actions
victoriadrake/django-security-check v1.1.1 💰
Helps find and remediate common security vulnerabilities in your Django application.
10 versions - Latest release: about 5 years ago - 11 dependent repositories - 91 stars on GitHub
carhartl/talisman-secrets-scan-action v1.4.0
Scan an incoming range of commits for accidentally added secrets and sensitive information
7 versions - Latest release: over 3 years ago - 8 dependent repositories - 3 stars on GitHub
xygeni/xygeni-action v6.4.0
Runs Xygeni Scanner
11 versions - Latest release: 6 months ago - 1 dependent repositories - 5 stars on GitHub
stacklok/frizbee-action v0.0.6
Automatically correct GitHub Actions and container image tags to digests
6 versions - Latest release: 5 months ago - 5 stars on GitHub
Top 5.9% on github actions
ForAllSecure/mapi-action v2.0.0
Automatically test your REST APIs with your OpenAPI specs and Postman collections
18 versions - Latest release: about 3 years ago - 88 dependent repositories - 27 stars on GitHub
yu-iskw/action-terrascan v1.2.2
TODO: 🐶 Run terrascan with reviewdog on pull requests to improve code review experience.
15 versions - Latest release: over 4 years ago - 1 stars on GitHub
tagdots/update-pre-commit-action 1.0.28
Run update-pre-commit to keep pre-commit hooks up to date and optionally create pull request
7 versions - Latest release: 10 months ago - 0 stars on GitHub
Top 2.7% on github actions
gensecaihq/Shai-Hulud-2.0-Detector v2.2.0
Detect Shai-Hulud npm supply chain attacks (2.0 + ChainDrop) - 1,240+ packages, SHA256 hashing, I...
9 versions - Latest release: 29 days ago - 149 stars on GitHub
simonkowallik/irulescan-action v3
Use irulescan to check F5 iRules for security issues.
2 versions - Latest release: about 1 year ago - 1 dependent repositories - 2 stars on GitHub
Top 3.7% on github actions
PaloAltoNetworks/prisma-cloud-scan v1.9.0
Scan container images for vulnerabilities and compliance issues
30 versions - Latest release: 5 months ago - 24 dependent repositories - 62 stars on GitHub
Threagile/run-threagile-action v1
Threat model analysis via open-source toolkit Threagile
1 version - Latest release: almost 6 years ago - 13 stars on GitHub
Top 9.3% on github actions
GitGuardian/gg-shield-action v1.42.0
Scan commits for secrets and other issues.
43 versions - Latest release: about 1 year ago - 338 stars on GitHub
xvnpw/ai-threat-modeling-action v1.3.4
AI featured threat modeling and security review action
24 versions - Latest release: over 2 years ago - 1 dependent repositories - 48 stars on GitHub
Top 6.6% on github actions
Legit-Labs/legitify v1.0.11
Legitify GitHub Action
34 versions - Latest release: about 2 years ago - 1 dependent repositories - 878 stars on GitHub
Top 4.1% on github actions
apisec-inc/apisec-run-scan v1.0.7
Continuous, automated, comprehensive API Security Testing
8 versions - Latest release: over 3 years ago - 114 dependent repositories - 28 stars on GitHub
Top 4.5% on github actions
PortSwigger/dastardly-github-action v1.0.0
Runs a Dastardly scan against a target site
1 version - Latest release: almost 4 years ago - 5 dependent repositories - 296 stars on GitHub
Top 3.4% on github actions
zaproxy/action-api-scan v0.10.0 💰
Scans the web application with the ZAP API Scan
12 versions - Latest release: 11 months ago - 70 dependent repositories - 75 stars on GitHub
Top 2.5% on github actions
kitabisa/sonarqube-action v1.2.1
Scan your code with SonarQube Scanner to detect bugs, vulnerabilities and code smells in more tha...
11 versions - Latest release: almost 3 years ago - 59 dependent repositories - 159 stars on GitHub
secret-scanner/action 0.2.1
Scan for secrets in a repository
7 versions - Latest release: about 4 years ago - 25 dependent repositories - 7 stars on GitHub
Top 5.4% on github actions
DariuszPorowski/github-action-gitleaks v2.1.0
Run Gitleaks in your CI/CD workflow
12 versions - Latest release: over 1 year ago - 62 dependent repositories - 22 stars on GitHub
Top 4.7% on github actions
djdefi/gitavscan v23 💰
Anti Virus scan for malicious files in a Git repository
23 versions - Latest release: 7 months ago - 68 dependent repositories - 54 stars on GitHub
gbrls/cabueta v1.1.0
Security Scanning in your CI/CD
3 versions - Latest release: over 3 years ago - 9 stars on GitHub
Top 9.9% on github actions
SecureStackCo/actions-secrets v0.1.3 removed
Scan your source code for sensitive data like API keys, passwords, server host strings, config an...
5 versions - Latest release: over 4 years ago - 13 dependent repositories - 22 stars on GitHub
albuch/sbt-dependency-check-action v1.0
Github action to execute sbt-dependency-check as part of a github workflow
1 version - Latest release: over 5 years ago - 3 dependent repositories - 1 stars on GitHub
trendmicro/cloudone-container-security-github-action 1.0.11
Scan container images with Vision One Container Security
12 versions - Latest release: almost 2 years ago - 7 stars on GitHub
SecureStackCo/actions-all-in-one v0.1.2
Scans your app for sensitive data & secrets, vulnerable third-party libraries, cloud misconfigura...
3 versions - Latest release: over 4 years ago - 15 stars on GitHub
koslib/ga-dtfy v1.0
Easily scan your assets with Detectify before shipping to production.
1 version - Latest release: about 5 years ago - 1 dependent repositories - 2 stars on GitHub
SecureStackCo/actions-code v0.1.1 removed
Scan your source code in real-time for vulnerable libraries & frameworks you are using. Supports ...
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 18 stars on GitHub
SecureStackCo/actions-log4j v0.1.4 removed
Scans your application for the presence of serious vulnerabilities in Log4j
5 versions - Latest release: over 4 years ago - 1 dependent repositories - 14 stars on GitHub
kfear1337/CodeQL v1.0.3 removed
GitHub Actions workflow for CodeQL security analysis.
3 versions - Latest release: almost 3 years ago - 1 stars on GitHub
magmanu/github-workflow-security-scanner v0.1.0 removed
A GitHub Action that performs static analysis on your workflows
1 version - Latest release: over 3 years ago - 0 stars on GitHub