Ecosyste.ms: Packages

An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

github actions "security" keyword

Top 2.2% on github actions
bridgecrewio/bridgecrew-action v1.2343.0
Find and fix security and compliance issues in infrastructure as code, open source packages, cont...
1,100 versions - Latest release: 6 months ago - 114 dependent repositories - 71 stars on GitHub
Top 3.8% on github actions
pypa/gh-action-pip-audit v1.0.8 💰
Use pip-audit to scan Python dependencies for known vulnerabilities
15 versions - Latest release: about 1 year ago - 131 dependent repositories - 51 stars on GitHub
tj-actions/bandit v5.5 💰
A security linter from PyCQA
15 versions - Latest release: 9 months ago - 40 dependent repositories - 3 stars on GitHub
hahwul/zest-env v1.1.4 💰
Zest CLI in Github action
7 versions - Latest release: about 1 month ago - 8 stars on GitHub
hashicorp/setup-signore v2.1.0
setup-signore downloads, installs, and configures the signore signing service client
10 versions - Latest release: about 1 year ago - 9 dependent repositories - 0 stars on GitHub
Top 4.6% on github actions
sigstore/gh-action-sigstore-python v2.1.1
Use sigstore-python to sign Python packages
26 versions - Latest release: 6 months ago - 143 dependent repositories - 32 stars on GitHub
HCL-TECH-SOFTWARE/appscan-sast-action v1.0.4
Scan for security issues in code
5 versions - Latest release: 2 months ago - 7 dependent repositories - 3 stars on GitHub
Top 7.2% on github actions
jbergstroem/hadolint-gh-action v1.12.2
A stable, well-tested, highly configurable way of checking your Dockerfile(s) with Hadolint
20 versions - Latest release: 4 months ago - 74 dependent repositories - 12 stars on GitHub
xen0l/iam-lint v2
Github Action to lint AWS IAM policy document files with parliament from DUo Labs
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 33 stars on GitHub
Top 5.0% on github actions
jpetrucciani/bandit-check 1.7.8 💰
GitHub action to lint your python code with bandit
10 versions - Latest release: 3 months ago - 84 dependent repositories - 12 stars on GitHub
Top 3.5% on github actions
stackrox/kube-linter-action v1.0.5
Scan directory or file with kube-linter
9 versions - Latest release: 3 months ago - 65 dependent repositories - 29 stars on GitHub
Top 0.3% on github actions
aquasecurity/trivy-action 0.20.0
Scans container images for vulnerabilities with Trivy
61 versions - Latest release: about 1 month ago - 3,327 dependent repositories - 687 stars on GitHub
Top 1.3% on github actions
zaproxy/action-full-scan v0.10.0 💰
Scans the web application with the ZAP Full Scan
11 versions - Latest release: 2 months ago - 215 dependent repositories - 238 stars on GitHub
Top 3.4% on github actions
zaproxy/action-api-scan v0.7.0 💰
Scans the web application with the ZAP API Scan
9 versions - Latest release: 2 months ago - 70 dependent repositories - 37 stars on GitHub
SecureStackCo/actions-sbom v0.2.0
Create a Software Bill of Materials (SBOM) with SecureStack
4 versions - Latest release: almost 2 years ago - 1 dependent repositories - 19 stars on GitHub
xen0l/dlint-check 0.10.1
Github Action to lint Python code with dlint from Duo Labs
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 2 stars on GitHub
secrethub/actions v0.2.1
Load secrets into your GitHub workflows
3 versions - Latest release: over 3 years ago - 46 stars on GitHub
Top 6.6% on github actions
Legit-Labs/legitify v1.0.7
Legitify GitHub Action
31 versions - Latest release: 6 months ago - 1 dependent repositories - 715 stars on GitHub
Top 0.8% on github actions
oxsecurity/megalinter v7.11.1 💰
Combine all available linters to automatically validate your sources without configuration !
158 versions - Latest release: about 2 months ago - 224 dependent repositories - 1,731 stars on GitHub
grolston/guard-action 1.0
Guard ShiftLeft
1 version - Latest release: almost 2 years ago - 1 dependent repositories - 2 stars on GitHub
embold/github-action-docker v0.2
Embold design and code quality scanning engine
2 versions - Latest release: over 2 years ago - 1 dependent repositories - 2 stars on GitHub
kahu-app/github-action v0.3.1
Dependency security check
8 versions - Latest release: 10 months ago - 0 stars on GitHub
UlisesGascon/openssf-scorecard-monitor v1.0.1
Monitor OpenSSF Scorecard Evolution over time
9 versions - Latest release: over 1 year ago - 3 dependent repositories - 22 stars on GitHub
georgealton/iam-sarif-report v2.3.2
Generate SARIF from AWS IAM Access Analyzer findings
12 versions - Latest release: 2 months ago - 5 stars on GitHub
Top 7.9% on github actions
victoriadrake/hugo-remote v1.1.1 💰
🚀 Build and deploy a Hugo site to a remote repository with latest extended Hugo.
5 versions - Latest release: over 3 years ago - 1 dependent repositories - 59 stars on GitHub
hoeg/semgrep-report v1.0.2
Report Semgrep findimgs to PRs with suggested changes
5 versions - Latest release: 12 months ago - 0 stars on GitHub
Top 9.1% on github actions
nowsecure/nowsecure-sbom-action v2.0.0
Generate a Mobile SBOM for an application and submit to the Dependency submission API
8 versions - Latest release: over 1 year ago - 9 dependent repositories - 9 stars on GitHub
alessiodionisi/setup-age-action v1.3.0 💰
Setup age and add it to the PATH
5 versions - Latest release: 4 months ago - 1 dependent repositories - 7 stars on GitHub
xvnpw/ai-threat-modeling-action v1.3.4
AI featured threat modeling and security review action
24 versions - Latest release: 3 months ago - 1 dependent repositories - 22 stars on GitHub
Top 2.5% on github actions
kitabisa/sonarqube-action v1.2.1
Scan your code with SonarQube Scanner to detect bugs, vulnerabilities and code smells in more tha...
11 versions - Latest release: 9 months ago - 59 dependent repositories - 122 stars on GitHub
Top 1.7% on github actions
stelligent/cfn_nag v0.8.10 removed
Execute cfn_nag_scan against the code in the repository where the GitHub Action workflow is run.
350 versions - Latest release: about 2 years ago - 45 dependent repositories - 1,170 stars on GitHub
piraces/kube-score-ga v0.1.3 💰
Uses the kube-score analysis tool to perform static code analysis of your Kubernetes object defin...
4 versions - Latest release: over 1 year ago - 5 dependent repositories - 9 stars on GitHub
Top 0.3% on github actions
securego/gosec v2.20.0 💰
Runs the gosec security checker
36 versions - Latest release: 26 days ago - 764 dependent repositories - 7,434 stars on GitHub
Top 1.0% on github actions
zaproxy/action-baseline v0.12.0 💰
Scans the web application with the ZAP Baseline Scan
15 versions - Latest release: 2 months ago - 497 dependent repositories - 281 stars on GitHub
Top 0.6% on github actions
ossf/scorecard-action v2.3.3
Run OSSF Scorecard checks and output results in SARIF format
29 versions - Latest release: about 1 month ago - 6,465 dependent repositories - 227 stars on GitHub
Top 0.3% on github actions
google-github-actions/auth v2.1.3
Authenticate to Google Cloud from GitHub Actions via Workload Identity Federation or service acco...
34 versions - Latest release: 26 days ago - 4,745 dependent repositories - 835 stars on GitHub
Traceableai/ast-action 0.0.5
GitHub action for Traceable Active Security Testing
6 versions - Latest release: about 1 year ago - 1 dependent repositories - 5 stars on GitHub
Top 1.1% on github actions
gitleaks/gitleaks-action v2.3.4
run gitleaks on push and pull-request events
38 versions - Latest release: 4 months ago - 211 dependent repositories - 243 stars on GitHub
silverhack/monkey365 v0.91.2-beta
Install and run PSScriptAnalyzer
5 versions - Latest release: 6 months ago - 630 stars on GitHub
kattecon/gh-app-access-token-gen v1.0.0
Generates a GitHub Access Token for a Github App based upon specific inputs.
2 versions - Latest release: about 1 year ago - 1 dependent repositories - 1 stars on GitHub
Top 5.5% on github actions
andrewmcodes/bundler-audit-action v0.1.0 💰
GitHub Action for running bundler-audit
2 versions - Latest release: almost 4 years ago - 19 dependent repositories - 14 stars on GitHub
Top 6.5% on github actions
Contrast-Security-OSS/contrastscan-action v3.0.1
Perform SAST analysis of a project
10 versions - Latest release: 4 months ago - 34 dependent repositories - 19 stars on GitHub
f-actions/opentype-sanitizer v3.0.0
A GitHub Action for opentype-sanitizer testing of font artifacts
8 versions - Latest release: 4 months ago - 1 dependent repositories - 6 stars on GitHub
NeuraLegion/wait-for v1
Run a Nexploit scan right in GitHub Action
1 version - Latest release: about 4 years ago - 0 stars on GitHub
Top 3.2% on github actions
trunk-io/trunk-action v1.1.14
The official trunk.io GitHub action
32 versions - Latest release: about 1 month ago - 73 dependent repositories - 216 stars on GitHub
Top 4.7% on github actions
djdefi/gitavscan 19 💰
Anti Virus scan for malicious files in a Git repository
19 versions - Latest release: 3 months ago - 68 dependent repositories - 35 stars on GitHub
sudo-bot/action-docker-sign latest
Sign docker images
1 version - Latest release: about 3 years ago - 10 dependent repositories - 6 stars on GitHub
NeuraLegion/stop-scan v1
Stops Nexploit Scan
1 version - Latest release: about 4 years ago - 0 stars on GitHub
Top 0.7% on github actions
trufflesecurity/trufflehog v3.75.1
Scan Github Actions with TruffleHog.
214 versions - Latest release: about 1 month ago - 519 dependent repositories - 13,224 stars on GitHub
Top 5.9% on github actions
ForAllSecure/mapi-action v2.0.0
Automatically test your REST APIs with your OpenAPI specs and Postman collections
18 versions - Latest release: 12 months ago - 88 dependent repositories - 24 stars on GitHub
Novusvetus/action-phpinsights 1.1.16 💰
Runs PHP Insights
18 versions - Latest release: 7 months ago - 3 dependent repositories - 7 stars on GitHub
gacts/gitleaks v1.2.0
Installs and runs GitLeaks in your actions workflow
11 versions - Latest release: 7 months ago - 70 dependent repositories - 11 stars on GitHub
DIVD-NL/cna-bot v1.4.7
A Bot that validates CVE records and (optionally) submits them to the CVE database.
36 versions - Latest release: 5 months ago - 1 dependent repositories - 2 stars on GitHub
dlint-py/dlint-action 1.0.0
A tool for encouraging best coding practices and helping ensure we're writing secure Python code.
1 version - Latest release: over 4 years ago - 1 dependent repositories - 0 stars on GitHub
mnavarrocarter/authorize-aws-security-group-ingress-action v1.1.0
Creates a inbound rule in an AWS Security Group and deletes it when the job finishes
2 versions - Latest release: 3 months ago - 6 stars on GitHub
Top 7.8% on github actions
SAP/fosstars-rating-core-action v1.14.0
The action calculates one of the Fosstars ratings. It outputs a report in Markdown format and an ...
18 versions - Latest release: 10 months ago - 17 dependent repositories - 7 stars on GitHub
Top 8.5% on github actions
parasoft/run-cpptest-action 2.0.1
A GitHub Action for running Parasoft C/C++test to ensure code quality and compliance with MISRA, ...
17 versions - Latest release: about 1 year ago - 5 dependent repositories - 8 stars on GitHub
bugale/bugalint v2.1.0
Convert various linter outputs to standard formats
4 versions - Latest release: 9 months ago - 1 dependent repositories - 3 stars on GitHub
Pwd9000-ML/azure-vm-password-rotate v1.1.0
Rotate AZURE virtual machines local administrator Passwords, using AZURE key vault
4 versions - Latest release: over 2 years ago - 1 dependent repositories - 3 stars on GitHub
occmundial/action-cve-clone v2.0.2
Send GitHub vulnerability alerts to multiple platforms like Slack, PagerDuty.
6 versions - Latest release: over 1 year ago - 0 stars on GitHub
parasoft/run-dottest-action 2.0.1
A GitHub Action for running Parasoft dotTEST analysis.
8 versions - Latest release: 12 months ago - 1 dependent repositories - 2 stars on GitHub
Top 3.8% on github actions
philips-labs/slsa-provenance-action v0.9.0
An action to generate SLSA build provenance for an artifact
24 versions - Latest release: 6 months ago - 39 dependent repositories - 43 stars on GitHub
jetstack/paranoia v0.2.1
Validate the presence or absence of certificate authorities in your container image.
6 versions - Latest release: over 1 year ago - 195 stars on GitHub
Top 2.7% on github actions
microsoft/security-devops-action v1.10.0
Run security analyzers.
12 versions - Latest release: 7 months ago - 42 dependent repositories - 80 stars on GitHub
Top 8.9% on github actions
ossillate-inc/packj-github-action v0.0.12-beta
Use Packj to avoid malicious and other "risky" open-source software dependencies
13 versions - Latest release: 9 months ago - 23 dependent repositories - 6 stars on GitHub
Threagile/run-threagile-action v1
Threat model analysis via open-source toolkit Threagile
1 version - Latest release: over 3 years ago - 11 stars on GitHub
geritol/write-guard v0.4.0
Enforce file level write access for monorepos
6 versions - Latest release: over 2 years ago - 1 dependent repositories - 8 stars on GitHub
daltonmenezes/discord-guardian-action v1.1.0 💰
Fetches the list of malicious domains on Discord in different providers and creates/updates a JSO...
3 versions - Latest release: over 2 years ago - 1 dependent repositories - 7 stars on GitHub
Contrast-Security-OSS/integration-verify-github-action v0.6.7
Verify Contrast Application by Job Outcome Policy or Vulnerability Count
12 versions - Latest release: 3 months ago - 2 stars on GitHub
awslabs/aws-lc-verification removed
Check SAW proofs to verify AWS-LC against Cryptol specs
Latest release: 8 months ago - 13 stars on GitHub
Top 4.4% on github actions
sysdiglabs/scan-action v3.6.0
Perform image analysis on locally built container image and post the result of the analysis to Sy...
11 versions - Latest release: 7 months ago - 66 dependent repositories - 25 stars on GitHub
Top 4.1% on github actions
reviewdog/action-detect-secrets v0.20.0
🐶 Run detect-secrets with reviewdog on pull requests to improve code review experience.
66 versions - Latest release: about 2 months ago - 82 dependent repositories - 20 stars on GitHub
SecureStackCo/actions-code v0.1.1
Scan your source code in real-time for vulnerable libraries & frameworks you are using. Supports ...
2 versions - Latest release: over 2 years ago - 1 dependent repositories - 18 stars on GitHub
VCTLabs/bandit-report-artifacts v0.0.2
Github action to find common security issues in Python code and get its report as a artifact.
3 versions - Latest release: over 3 years ago - 4 dependent repositories - 1 stars on GitHub
Aptori-dev/sift-action v1.0.1
Find business logic and security bugs in your application with Aptori Autonomous API Security Tes...
3 versions - Latest release: 10 months ago - 6 stars on GitHub
Top 6.1% on github actions
Checkmarx/ast-github-action 2.0.26
Simplify Checkmarx Scanning of source code along with Result consumption leveraging Checkmarx AST...
58 versions - Latest release: about 1 month ago - 22 dependent repositories - 9 stars on GitHub
Top 5.2% on github actions
checkmarx/ast-github-action 2.0.26
Simplify Checkmarx Scanning of source code along with Result consumption leveraging Checkmarx AST...
58 versions - Latest release: about 1 month ago - 73 dependent repositories - 9 stars on GitHub
Top 8.5% on github actions
federacy/scan-action 0.1.5
SAST and Dependency Scanning
6 versions - Latest release: about 1 year ago - 7 dependent repositories - 11 stars on GitHub
SecureStackCo/actions-abom v0.1.5
Create an Application Bill of Materials (ABOM) with SecureStack
6 versions - Latest release: almost 2 years ago - 10 stars on GitHub
Top 4.7% on github actions
pyupio/safety 3.2.0 💰
Runs the Safety CLI dependency scanner against your project
61 versions - Latest release: about 1 month ago - 3 dependent repositories - 1,572 stars on GitHub
Top 9.5% on github actions
erzz/dockle-action v1.4.0
Lint & Best Practices for container images with integrations to Github UI
9 versions - Latest release: 10 months ago - 88 dependent repositories - 10 stars on GitHub
trendmicro/cloudone-container-security-github-action 1.0.10
Scan container images with Vision One Container Security
11 versions - Latest release: 8 months ago - 4 stars on GitHub
standardnotes/brakeman-action v1.0.0 💰
A GitHub action to run Brakeman, a static analysis security vulnerability scanner for Ruby on Rai...
1 version - Latest release: about 3 years ago - 2 dependent repositories - 4 stars on GitHub
saucelabs/sauce-security-action v0.3.0
A GitHub action to run security scans on your applications.
3 versions - Latest release: almost 3 years ago - 3 stars on GitHub
Top 9.5% on github actions
y-mehta/vulnalerts v1
Customized daily Vulnerabilty Alerts straight to your Slack Inbox for Free.
1 version - Latest release: over 4 years ago - 1 dependent repositories - 13 stars on GitHub
Top 7.1% on github actions
checkmarx-ts/checkmarx-github-action v1.0.6
Find vulnerabilities in your code using Checkmarx SAST solution
7 versions - Latest release: about 3 years ago - 3 dependent repositories - 24 stars on GitHub
GorillaStack/github-action-apply-on-merge v0.1.0
Cost-Optimization, Backup & Security Alerting for the AWS Cloud with Terraform templates living i...
1 version - Latest release: almost 5 years ago - 15 stars on GitHub
hahwul/mzap v1.3.1 💰
Multiple target ZAP Scanning
10 versions - Latest release: 9 months ago - 92 stars on GitHub
kitabisa/gokart-action v1.0.0
Scan your code with GoKart to finds vulnerabilities using the SSA (single static assignment) form...
1 version - Latest release: almost 3 years ago - 1 dependent repositories - 9 stars on GitHub
Top 6.3% on github actions
victoriadrake/link-snitch v1.1.0 💰
Scans your site for broken links so you can fix them.
3 versions - Latest release: over 2 years ago - 9 dependent repositories - 58 stars on GitHub
HCL-TECH-SOFTWARE/appscan-dast-action v1.0.5
Scan for security issues in web applications
6 versions - Latest release: about 1 year ago - 4 dependent repositories - 1 stars on GitHub
venura9/manage-nsg v1.2
Add/Remove NSG Rules using the public IP of the hosted runner
6 versions - Latest release: almost 4 years ago - 3 dependent repositories - 4 stars on GitHub
ghr-actions/settings-check v0.1.0
Checks that a GitHub repos settings line up with a specification
1 version - Latest release: about 3 years ago - 1 dependent repositories - 2 stars on GitHub
CrowdStrike/container-image-scan-action v1.2.0
Scan your container image for vulnerabilities and malware
12 versions - Latest release: 3 months ago - 1 dependent repositories - 11 stars on GitHub
Top 7.2% on github actions
GeekMasher/advanced-security-compliance v1.7.0
ghascompliance
13 versions - Latest release: over 1 year ago - 1 dependent repositories - 124 stars on GitHub
operatorequals/gitsign-action v0.3.0
Uses `gitsign` to verify commit signatures of a branch
3 versions - Latest release: over 1 year ago - 1 dependent repositories - 4 stars on GitHub
bashofmann/neuvector-image-scan-action
Scans a container image for vulnerabilities with [NeuVector](https://neuvector.com)
Latest release: 23 days ago - 1 stars on GitHub
gioragutt/scan-unverified-actions v1 removed
Scans your Github Actions Workflows for unverified actions
1 version - Latest release: almost 3 years ago - 1 dependent repositories - 1 stars on GitHub
JosiahSiegel/runleaks v1.0.1
Identify potential leaks in GitHub action logs
5 versions - Latest release: about 1 year ago - 0 stars on GitHub
SecureStackCo/actions-log4j v0.1.4
Scans your application for the presence of serious vulnerabilities in Log4j
5 versions - Latest release: over 2 years ago - 1 dependent repositories - 14 stars on GitHub