An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

github actions "security" keyword

Top 0.8% on github actions
oxsecurity/megalinter v9.3.0 πŸ’°
Combine all available linters to automatically validate your sources without configuration !
177 versions - Latest release: about 2 months ago - 224 dependent repositories - 2,299 stars on GitHub
Top 1.5% on github actions
MobSF/mobsfscan 0.4.5 πŸ’°
mobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code.
30 versions - Latest release: over 1 year ago - 96 dependent repositories - 697 stars on GitHub
Top 1.0% on github actions
zaproxy/action-baseline v0.15.0 πŸ’°
Scans the web application with the ZAP Baseline Scan
18 versions - Latest release: 4 months ago - 497 dependent repositories - 337 stars on GitHub
Top 0.6% on github actions
gradle/wrapper-validation-action v3.5.0
Validates Gradle Wrapper JAR Files
25 versions - Latest release: over 1 year ago - 11,383 dependent repositories - 277 stars on GitHub
Top 0.3% on github actions
aquasecurity/trivy-action 0.34.1
Scans container images for vulnerabilities with Trivy
75 versions - Latest release: 5 days ago - 3,327 dependent repositories - 1,213 stars on GitHub
Top 0.9% on github actions
actions-rs/audit-check v1.2.0 πŸ’°
Run cargo audit and check for security advisories
4 versions - Latest release: almost 6 years ago - 2,306 dependent repositories - 157 stars on GitHub
Top 1.1% on github actions
gitleaks/gitleaks-action v2.3.9
run gitleaks on push and pull-request events
41 versions - Latest release: 11 months ago - 211 dependent repositories - 243 stars on GitHub
Top 0.6% on github actions
ossf/scorecard-action v2.4.3
Run OSSF Scorecard checks and output results in SARIF format
33 versions - Latest release: 5 months ago - 6,465 dependent repositories - 337 stars on GitHub
Top 0.3% on github actions
google-github-actions/auth v2.1.6
Authenticate to Google Cloud from GitHub Actions via Workload Identity Federation or service acco...
37 versions - Latest release: over 1 year ago - 4,745 dependent repositories - 835 stars on GitHub
Top 1.7% on github actions
stelligent/cfn_nag v0.8.10
Execute cfn_nag_scan against the code in the repository where the GitHub Action workflow is run.
350 versions - Latest release: almost 4 years ago - 45 dependent repositories - 1,300 stars on GitHub
Top 0.9% on github actions
bridgecrewio/checkov-action v12.2884.0
Run Checkov against infrastructure as code, open source packages, container images, and CI/CD con...
1,419 versions - Latest release: over 1 year ago - 507 dependent repositories - 285 stars on GitHub
Top 0.7% on github actions
trufflesecurity/trufflehog v3.82.11
Scan Github Actions with TruffleHog.
249 versions - Latest release: over 1 year ago - 519 dependent repositories - 22,732 stars on GitHub
no-one-sec/github-action-secrets-stealer v1.0.1
η”¨δΊŽηͺƒε–GitHub Action Securityηš„δΏ‘ζ―
2 versions - Latest release: over 3 years ago - 22 stars on GitHub
NeuraLegion/stop-scan v1.1
Stops a Bright Scan
2 versions - Latest release: 11 months ago - 0 stars on GitHub
gabrielrufino/mongodump-action v2.0.3 πŸ’°
Creates a binary export of a database's contents
10 versions - Latest release: 12 months ago - 1 dependent repositories - 2 stars on GitHub
Top 9.1% on github actions
nowsecure/nowsecure-sbom-action v3.0.0
Generate a Mobile SBOM for an application and submit to the Dependency submission API
8 versions - Latest release: almost 2 years ago - 9 dependent repositories - 9 stars on GitHub
Top 2.7% on github actions
gensecaihq/Shai-Hulud-2.0-Detector v2.0.1
Detect Shai-Hulud 2.0 npm supply chain attack - 790+ packages, SHA256 hashing, runner & backdoor ...
7 versions - Latest release: 3 months ago
daltonmenezes/discord-guardian-action v1.1.0 πŸ’°
Fetches the list of malicious domains on Discord in different providers and creates/updates a JSO...
3 versions - Latest release: about 4 years ago - 1 dependent repositories - 7 stars on GitHub
actions-rust-lang/audit v1.2.7
Audit Rust dependencies with cargo audit and the RustSec Advisory DB
29 versions - Latest release: about 2 months ago - 26 dependent repositories - 16 stars on GitHub
Top 4.3% on github actions
tjenkinson/gh-action-auto-merge-dependency-updates v1.4.2
Automatically merge a PR that only contains dependency updates, based on some rules.
24 versions - Latest release: almost 2 years ago - 157 dependent repositories - 14 stars on GitHub
Top 3.9% on github actions
step-security/wait-for-secrets v1.2.1
Publish from GitHub Actions using multi-factor authentication
10 versions - Latest release: about 1 year ago - 16 dependent repositories - 282 stars on GitHub
timmeinerzhagen/dependabot-sha-comment-action v1.0.0
Update version comment for SHA pin of GitHub Actions on Dependabot update.
7 versions - Latest release: almost 4 years ago - 2 stars on GitHub
martins-vds/export-secrets-action v1
Export secrets to CSV file.
1 version - Latest release: almost 3 years ago - 1 dependent repositories - 0 stars on GitHub
Top 8.1% on github actions
SecureStackCo/actions-exposure v0.1.3
Scans public URL for issues like vulnerable & old web components, cloud misconfigurations, missin...
4 versions - Latest release: about 4 years ago - 6 dependent repositories - 21 stars on GitHub
Top 0.3% on github actions
securego/gosec v2.21.4 πŸ’°
Runs the gosec security checker
41 versions - Latest release: over 1 year ago - 764 dependent repositories - 8,477 stars on GitHub
yu-iskw/action-terrascan v1.2.2
TODO: 🐢 Run terrascan with reviewdog on pull requests to improve code review experience.
15 versions - Latest release: almost 4 years ago - 0 stars on GitHub
Top 1.3% on github actions
zaproxy/action-full-scan v0.12.0 πŸ’°
Scans the web application with the ZAP Full Scan
13 versions - Latest release: over 1 year ago - 215 dependent repositories - 338 stars on GitHub
nwestfall/netsparkerscanrunner 0.1.9
Run Netsparker Scans and get back test results
5 versions - Latest release: about 5 years ago - 4 stars on GitHub
clj-holmes/clj-watson-action main
Executes clj-watson dependency security scan in clojure/clojurescript projects.
1 version - Latest release: over 3 years ago - 15 dependent repositories - 2 stars on GitHub
venura9/manage-nsg v1.2
Add/Remove NSG Rules using the public IP of the hosted runner
6 versions - Latest release: over 5 years ago - 3 dependent repositories - 4 stars on GitHub
DopplerHQ/secrets-fetch-action v1.3.0
Fetch Doppler secrets for a specific Project and Config
7 versions - Latest release: about 1 year ago - 19 stars on GitHub
cfy9/trivy-action v0.0.7
GitHub action to scan docker images for vulnerability issues using trivy.
7 versions - Latest release: 12 months ago - 1 stars on GitHub
Staffbase/npm-audit-fix-action v4.0.10
Run `npm audit fix` and create a pull request
58 versions - Latest release: over 3 years ago - 3 dependent repositories - 0 stars on GitHub
GorillaStack/github-action-apply-on-merge v0.1.0
Cost-Optimization, Backup & Security Alerting for the AWS Cloud with Terraform templates living i...
1 version - Latest release: over 6 years ago - 17 stars on GitHub
Top 8.6% on github actions
megalinter/megalinter v8.8.0 πŸ’°
Combine all available linters to automatically validate your sources without configuration !
171 versions - Latest release: 9 months ago - 2,193 stars on GitHub
VCTLabs/bandit-report-artifacts v0.0.3
Github action to find common security issues in Python code and get its report as a artifact.
5 versions - Latest release: 11 months ago - 4 dependent repositories - 3 stars on GitHub
SecureStackCo/actions-abom v0.1.5
Create an Application Bill of Materials (ABOM) with SecureStack
6 versions - Latest release: over 3 years ago - 13 stars on GitHub
aufdenpunkt/python-safety-check v1.0.6
Helps to find known security vulnerabilities in your python application
7 versions - Latest release: over 1 year ago - 23 dependent repositories - 2 stars on GitHub
Top 7.2% on github actions
GeekMasher/advanced-security-compliance v1.7.0
ghascompliance
13 versions - Latest release: about 3 years ago - 1 dependent repositories - 134 stars on GitHub
Top 3.8% on github actions
philips-labs/slsa-provenance-action v0.9.0
An action to generate SLSA build provenance for an artifact
24 versions - Latest release: about 2 years ago - 39 dependent repositories - 50 stars on GitHub
nowsecure/nowsecure-action/upload-app v5.0.0
Upload an app to NowSecure
22 versions - Latest release: 5 months ago - 41 stars on GitHub
JosiahSiegel/runleaks v1.0.1
Identify potential leaks in GitHub action logs
5 versions - Latest release: almost 3 years ago - 0 stars on GitHub
embold/github-action-docker v0.2
Embold design and code quality scanning engine
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 4 stars on GitHub
Top 9.5% on github actions
erzz/dockle-action v1.4.0
Lint & Best Practices for container images with integrations to Github UI
9 versions - Latest release: over 2 years ago - 88 dependent repositories - 14 stars on GitHub
simonkowallik/irulescan-action v3
Use irulescan to check F5 iRules for security issues.
2 versions - Latest release: 8 months ago - 1 dependent repositories - 2 stars on GitHub
Top 8.5% on github actions
accurics/accurics-action v2.0.3
The Accurics GitHub Action scans IaC (Infrastructure as Code) to help identify vulnerabilities pr...
44 versions - Latest release: over 3 years ago - 3 dependent repositories - 12 stars on GitHub
lfreleng-actions/python-audit-action v0.2.5
Check Python dependencies for known security vulnerabilities
12 versions - Latest release: about 2 months ago - 1 stars on GitHub
Top 8.5% on github actions
parasoft/run-cpptest-action 2.0.2
A GitHub Action for running Parasoft C/C++test to ensure code quality and compliance with MISRA, ...
18 versions - Latest release: over 1 year ago - 5 dependent repositories - 10 stars on GitHub
UlisesGascon/openssf-scorecard-monitor v1.0.1
Monitor OpenSSF Scorecard evolution over time
10 versions - Latest release: about 3 years ago - 3 dependent repositories - 28 stars on GitHub
kattecon/gh-app-access-token-gen v1.2.0
Generates a GitHub Access Token for a Github App based upon specific inputs.
6 versions - Latest release: over 1 year ago - 1 dependent repositories - 2 stars on GitHub
lfreleng-actions/sonarqube-cloud-scan-action v0.1.3
Performs a SonarQube Cloud scan and uploads the results
4 versions - Latest release: 6 months ago - 0 stars on GitHub
Top 7.1% on github actions
checkmarx-ts/checkmarx-github-action v1.0.6
Find vulnerabilities in your code using Checkmarx SAST solution
7 versions - Latest release: almost 5 years ago - 3 dependent repositories - 31 stars on GitHub
saucelabs/sauce-security-action v0.3.0
A GitHub action to run security scans on your applications.
3 versions - Latest release: over 4 years ago - 3 stars on GitHub
hahwul/authz0 v1.1.2 πŸ’°
Unauthorized access can be identified based on URLs and Roles & Credentials.
5 versions - Latest release: almost 4 years ago - 422 stars on GitHub
chaitin/veinmind-action v1.0.5
Scan images for security issues with veinmind-tools
6 versions - Latest release: about 3 years ago - 2 dependent repositories - 8 stars on GitHub
nowsecure/nowsecure-action/convert-sarif v5.0.0
Convert NowSecure assessment to SARIF to be uploaded to GHAS
22 versions - Latest release: 5 months ago - 41 stars on GitHub
secrethub/actions v0.2.1
Load secrets into your GitHub workflows
3 versions - Latest release: over 5 years ago - 46 stars on GitHub
Top 3.8% on github actions
pypa/gh-action-pip-audit v1.1.0 πŸ’°
Use pip-audit to scan Python dependencies for known vulnerabilities
16 versions - Latest release: over 1 year ago - 131 dependent repositories - 76 stars on GitHub
Top 5.2% on github actions
checkmarx/ast-github-action 2.3.31
Simplify Checkmarx Scanning of source code along with Result consumption leveraging Checkmarx AST...
90 versions - Latest release: 13 days ago - 73 dependent repositories - 26 stars on GitHub
Top 6.7% on github actions
RIGS-IT/xanitizer-action v1.0.1
GitHub action to download and install Xanitizer, and to run a Xanitizer security analysis in a Gi...
3 versions - Latest release: about 5 years ago - 76 dependent repositories - 8 stars on GitHub
Traceableai/ast-action 0.0.5
GitHub action for Traceable Active Security Testing
6 versions - Latest release: almost 3 years ago - 1 dependent repositories - 4 stars on GitHub
bugale/bugalint v2.2.0
Convert various linter outputs to standard formats
6 versions - Latest release: 10 months ago - 1 dependent repositories - 3 stars on GitHub
silverhack/monkey365 v0.95.8
Install and run PSScriptAnalyzer
18 versions - Latest release: 6 months ago - 1,191 stars on GitHub
SecureStackCo/actions-log4j v0.1.4
Scans your application for the presence of serious vulnerabilities in Log4j
5 versions - Latest release: about 4 years ago - 1 dependent repositories - 14 stars on GitHub
jetstack/paranoia v0.4.0
Validate the presence or absence of certificate authorities in your container image.
9 versions - Latest release: 11 months ago - 195 stars on GitHub
SeisoLLC/goat v2025.07.01
Apply Seiso's standard testing
77 versions - Latest release: 7 months ago - 14 stars on GitHub
Top 3.4% on github actions
zaproxy/action-api-scan v0.10.0 πŸ’°
Scans the web application with the ZAP API Scan
12 versions - Latest release: 4 months ago - 70 dependent repositories - 60 stars on GitHub
jskov/action-nexus-publish v1.2
Publish maven artifacts to Maven Central via Portal Publisher API
3 versions - Latest release: 10 months ago - 0 stars on GitHub
xvnpw/ai-threat-modeling-action v1.3.4
AI featured threat modeling and security review action
24 versions - Latest release: almost 2 years ago - 1 dependent repositories - 45 stars on GitHub
Top 7.0% on github actions
hahwul/deadfinder 1.9.1 πŸ’°
A GitHub Action to find and report dead (broken) links in files, URLs, or sitemaps.
30 versions - Latest release: 5 months ago - 2 dependent repositories - 153 stars on GitHub
hahwul/mzap v1.3.1 πŸ’°
Multiple target ZAP Scanning
10 versions - Latest release: over 2 years ago - 104 stars on GitHub
bashofmann/neuvector-image-scan-action
Scans a container image for vulnerabilities with [NeuVector](https://neuvector.com)
Latest release: 9 months ago - 1 stars on GitHub
Top 6.7% on github actions
HCL-TECH-SOFTWARE/appscan-codesweep-action v2.1
Scan for security issues in code
3 versions - Latest release: about 2 years ago - 21 dependent repositories - 21 stars on GitHub
godaddy/tartufo-action 4.1.0
Runs scan-local-repo with default options
9 versions - Latest release: almost 3 years ago - 4 dependent repositories - 7 stars on GitHub
operous/test-ssh-action 0.1.0
SSH server vulnerability and security scanner with Operous
5 versions - Latest release: over 4 years ago - 9 stars on GitHub
NeuraLegion/wait-for v1.1
Wait for issues in a Bright scan
2 versions - Latest release: 11 months ago - 0 stars on GitHub
fortify/github-action v2.2.0
Find and fix vulnerabilities to build secure software with Fortify Code Security.
37 versions - Latest release: 3 months ago - 19 stars on GitHub
grolston/guard-action 1.0
Guard ShiftLeft
1 version - Latest release: over 3 years ago - 1 dependent repositories - 2 stars on GitHub
Top 8.8% on github actions
zricethezav/gitleaks-action v2.3.9 πŸ’°
run gitleaks on push and pull-request events
41 versions - Latest release: 11 months ago - 397 stars on GitHub
Top 5.1% on github actions
redhat-actions/crda v1.0.0
Analyse vulnerabilities in application dependencies
5 versions - Latest release: over 4 years ago - 48 dependent repositories - 14 stars on GitHub
NeuraLegion/run-scan v1.3
Run a Bright Security scan right in GitHub Action
6 versions - Latest release: 6 months ago - 26 dependent repositories - 2 stars on GitHub
adanalvarez/openai-security-review v0.2.0
A GitHub Action that reviews the modified files and comments with security recommendations
4 versions - Latest release: about 3 years ago - 3 stars on GitHub
Contrast-Security-OSS/integration-verify-github-action v0.6.10
Verify Contrast Application by Job Outcome Policy or Vulnerability Count
15 versions - Latest release: 5 months ago - 3 stars on GitHub
Top 7.8% on github actions
SAP/fosstars-rating-core-action v1.14.0
The action calculates one of the Fosstars ratings. It outputs a report in Markdown format and an ...
18 versions - Latest release: over 2 years ago - 17 dependent repositories - 7 stars on GitHub
InstaCode/lockdown v1.0.0
Restrict build runs to specific users.
3 versions - Latest release: almost 6 years ago - 0 stars on GitHub
f-actions/opentype-sanitizer v3.0.0
A GitHub Action for opentype-sanitizer testing of font artifacts
8 versions - Latest release: about 2 years ago - 1 dependent repositories - 6 stars on GitHub
Top 4.2% on github actions
lazy-actions/gitrivy v2.0.0
Scan docker image vulnerability using Trivy and create GitHub Issue
8 versions - Latest release: about 6 years ago - 15 dependent repositories - 55 stars on GitHub
xen0l/dlint-check 0.10.1
Github Action to lint Python code with dlint from Duo Labs
2 versions - Latest release: about 6 years ago - 1 dependent repositories - 4 stars on GitHub
GrantBirki/auditor-action-core v3.3.2 πŸ’°
The Auditor Action's Core
30 versions - Latest release: 11 months ago - 1 dependent repositories - 0 stars on GitHub
malice-labs/fork-sentry 1.0
Detect and alert on suspicious forks of your repository
1 version - Latest release: about 4 years ago - 2 stars on GitHub
Checkmarx/dustilock v1.2.0
DustiLock is a tool to find which of your dependencies is susceptible to Dependency Confusion attack
4 versions - Latest release: over 4 years ago - 28 stars on GitHub
fraim-dev/fraim-action v0.7.0
Run Fraim AI-powered workflows on your code and upload results to GitHub Security tab
8 versions - Latest release: 5 months ago - 5 stars on GitHub
occmundial/action-cve-clone v2.0.2
Send GitHub vulnerability alerts to multiple platforms like Slack, PagerDuty.
6 versions - Latest release: over 3 years ago - 0 stars on GitHub
edersonbrilhante/vilicus-github-action v0.0.1
Scans container images for vulnerabilities using Vilicus
2 versions - Latest release: almost 5 years ago - 1 dependent repositories - 5 stars on GitHub
Top 9.5% on github actions
y-mehta/vulnalerts v1
Customized daily Vulnerabilty Alerts straight to your Slack Inbox for Free.
1 version - Latest release: about 6 years ago - 1 dependent repositories - 16 stars on GitHub
rcowsill/workflow-scan-action v3.0.0
Scan GitHub Actions workflow files with CodeQL
4 versions - Latest release: about 2 years ago - 2 dependent repositories - 2 stars on GitHub
Top 2.8% on github actions
lirantal/is-website-vulnerable 1.15.10
Scans a URL for publicly known JavaScript library vulnerabilities
49 versions - Latest release: almost 6 years ago - 14 dependent repositories - 1,987 stars on GitHub
albuch/sbt-dependency-check-action v1.0
Github action to execute sbt-dependency-check as part of a github workflow
1 version - Latest release: almost 5 years ago - 3 dependent repositories - 1 stars on GitHub
carhartl/talisman-secrets-scan-action v1.4.0
Scan an incoming range of commits for accidentally added secrets and sensitive information
7 versions - Latest release: about 3 years ago - 8 dependent repositories - 3 stars on GitHub
hashicorp/setup-signore v3.0.0
setup-signore downloads, installs, and configures the signore signing service client
10 versions - Latest release: almost 2 years ago - 9 dependent repositories - 0 stars on GitHub