An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

github actions "security" keyword

View the packages on the github actions package registry that are tagged with the "security" keyword.

Top 0.9% on github actions
bridgecrewio/checkov-action v12.2884.0 removed
Run Checkov against infrastructure as code, open source packages, container images, and CI/CD con...
1,419 versions - Latest release: about 1 year ago - 507 dependent repositories - 285 stars on GitHub
VCTLabs/bandit-report-artifacts v0.0.3 removed
Github action to find common security issues in Python code and get its report as a artifact.
5 versions - Latest release: 10 months ago - 4 dependent repositories - 3 stars on GitHub
Top 1.7% on github actions
stelligent/cfn_nag v0.8.10 removed
Execute cfn_nag_scan against the code in the repository where the GitHub Action workflow is run.
350 versions - Latest release: over 3 years ago - 45 dependent repositories - 1,300 stars on GitHub
Top 7.1% on github actions
checkmarx-ts/checkmarx-github-action v1.0.6 removed
Find vulnerabilities in your code using Checkmarx SAST solution
7 versions - Latest release: almost 5 years ago - 3 dependent repositories - 31 stars on GitHub
Top 3.8% on github actions
pypa/gh-action-pip-audit v1.1.0 removed 💰
Use pip-audit to scan Python dependencies for known vulnerabilities
16 versions - Latest release: over 1 year ago - 131 dependent repositories - 76 stars on GitHub
bugale/bugalint v2.2.0 removed
Convert various linter outputs to standard formats
6 versions - Latest release: 8 months ago - 1 dependent repositories - 3 stars on GitHub
Top 7.8% on github actions
SAP/fosstars-rating-core-action v1.14.0 removed
The action calculates one of the Fosstars ratings. It outputs a report in Markdown format and an ...
18 versions - Latest release: over 2 years ago - 17 dependent repositories - 7 stars on GitHub
hahwul/authz0 v1.1.2 removed 💰
Unauthorized access can be identified based on URLs and Roles & Credentials.
5 versions - Latest release: almost 4 years ago - 422 stars on GitHub
parasoft/run-dottest-action 2.0.2 removed
A GitHub Action for running Parasoft dotTEST analysis.
9 versions - Latest release: 9 months ago - 1 dependent repositories - 3 stars on GitHub
Top 6.6% on github actions
Legit-Labs/legitify v1.0.11 removed
Legitify GitHub Action
34 versions - Latest release: over 1 year ago - 1 dependent repositories - 815 stars on GitHub
SeisoLLC/goat v2025.07.01 removed
Apply Seiso's standard testing
77 versions - Latest release: 6 months ago - 14 stars on GitHub
Top 4.3% on github actions
reload/github-security-jira v1.5.0 removed
Synchronize the current repo alert state with JIRA and creates tickets accordingly.
8 versions - Latest release: about 2 years ago - 13 dependent repositories - 54 stars on GitHub
InstaCode/lockdown v1.0.0 removed
Restrict build runs to specific users.
3 versions - Latest release: almost 6 years ago - 0 stars on GitHub
HCL-TECH-SOFTWARE/appscan-sast-action v1.0.7 removed
Scan for security issues in code
8 versions - Latest release: 9 months ago - 7 dependent repositories - 8 stars on GitHub
lfreleng-actions/sonatype-lifecycle-scan-action v0.1.2 removed
Runs a Sonatype Lifecycle (Nexus IQ) scan
3 versions - Latest release: 4 months ago - 0 stars on GitHub
secrethub/actions v0.2.1 removed
Load secrets into your GitHub workflows
3 versions - Latest release: about 5 years ago - 46 stars on GitHub
Top 0.7% on github actions
trufflesecurity/trufflehog v3.82.11 removed
Scan Github Actions with TruffleHog.
249 versions - Latest release: about 1 year ago - 519 dependent repositories - 22,732 stars on GitHub
Top 1.0% on github actions
zaproxy/action-baseline v0.14.0 removed 💰
Scans the web application with the ZAP Baseline Scan
17 versions - Latest release: about 1 year ago - 497 dependent repositories - 337 stars on GitHub
Top 0.3% on github actions
securego/gosec v2.21.4 💰
Runs the gosec security checker
41 versions - Latest release: over 1 year ago - 764 dependent repositories - 8,477 stars on GitHub
Top 4.1% on github actions
reviewdog/action-detect-secrets v0.29.0 removed 💰
🐶 Run detect-secrets with reviewdog on pull requests to improve code review experience.
89 versions - Latest release: 4 months ago - 82 dependent repositories - 24 stars on GitHub
simonkowallik/irulescan-action v3 removed
Use irulescan to check F5 iRules for security issues.
2 versions - Latest release: 6 months ago - 1 dependent repositories - 2 stars on GitHub
Top 2.6% on github actions
triat/terraform-security-scan v3.2.0 removed
Scan your terraform code with tfsec
22 versions - Latest release: about 1 year ago - 54 dependent repositories - 105 stars on GitHub
Top 2.8% on github actions
lirantal/is-website-vulnerable 1.15.10 removed
Scans a URL for publicly known JavaScript library vulnerabilities
49 versions - Latest release: almost 6 years ago - 14 dependent repositories - 1,987 stars on GitHub
Top 6.1% on github actions
Checkmarx/ast-github-action 2.3.26 removed
Simplify Checkmarx Scanning of source code along with Result consumption leveraging Checkmarx AST...
85 versions - Latest release: 4 months ago - 22 dependent repositories - 21 stars on GitHub
gacts/gitleaks v1.3.0 removed
Installs and runs GitLeaks in your actions workflow
17 versions - Latest release: 4 months ago - 70 dependent repositories - 16 stars on GitHub
xen0l/dlint-check 0.10.1 removed
Github Action to lint Python code with dlint from Duo Labs
2 versions - Latest release: almost 6 years ago - 1 dependent repositories - 4 stars on GitHub
reposaur/repo-audit-action v0.1.0 removed
Audit your organization's repositories using Reposaur.
1 version - Latest release: over 3 years ago - 1 stars on GitHub
kitabisa/gokart-action v1.0.0 removed
Scan your code with GoKart to finds vulnerabilities using the SSA (single static assignment) form...
1 version - Latest release: over 4 years ago - 1 dependent repositories - 9 stars on GitHub
piraces/kube-score-ga v0.1.3 removed 💰
Uses the kube-score analysis tool to perform static code analysis of your Kubernetes object defin...
4 versions - Latest release: over 3 years ago - 5 dependent repositories - 11 stars on GitHub
hahwul/mzap v1.3.1 removed 💰
Multiple target ZAP Scanning
10 versions - Latest release: over 2 years ago - 104 stars on GitHub
Top 2.9% on github actions
oke-py/npm-audit-action v3.0.0 removed
run npm audit
34 versions - Latest release: 8 months ago - 88 dependent repositories - 46 stars on GitHub
tenable/accurics-action v2.0.3 removed
The Accurics GitHub Action scans IaC (Infrastructure as Code) to help identify vulnerabilities pr...
44 versions - Latest release: about 3 years ago - 12 stars on GitHub
Top 1.5% on github actions
MobSF/mobsfscan 0.4.5 removed 💰
mobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code.
30 versions - Latest release: about 1 year ago - 96 dependent repositories - 697 stars on GitHub
hoeg/semgrep-report v1.0.2 removed
Report Semgrep findimgs to PRs with suggested changes
5 versions - Latest release: over 2 years ago - 0 stars on GitHub
gabrielrufino/mongodump-action v2.0.3 removed 💰
Creates a binary export of a database's contents
10 versions - Latest release: 10 months ago - 1 dependent repositories - 2 stars on GitHub
GorillaStack/github-action-apply-on-merge v0.1.0 removed
Cost-Optimization, Backup & Security Alerting for the AWS Cloud with Terraform templates living i...
1 version - Latest release: over 6 years ago - 17 stars on GitHub
Top 8.6% on github actions
megalinter/megalinter v8.8.0 removed 💰
Combine all available linters to automatically validate your sources without configuration !
171 versions - Latest release: 7 months ago - 2,193 stars on GitHub
jskov/action-nexus-publish v1.2 removed
Publish maven artifacts to Maven Central via Portal Publisher API
3 versions - Latest release: 9 months ago - 0 stars on GitHub
DVKunion/CollieTrickster v1.1.1 removed
Use Collie to get an free host
3 versions - Latest release: over 2 years ago - 38 stars on GitHub
UlisesGascon/openssf-scorecard-monitor v1.0.1 removed
Monitor OpenSSF Scorecard evolution over time
10 versions - Latest release: almost 3 years ago - 3 dependent repositories - 28 stars on GitHub
awslabs/aws-lc-verification removed
Check SAW proofs to verify AWS-LC against Cryptol specs
Latest release: about 2 years ago - 57 stars on GitHub
Top 5.1% on github actions
redhat-actions/crda v1.0.0 removed
Analyse vulnerabilities in application dependencies
5 versions - Latest release: over 4 years ago - 48 dependent repositories - 14 stars on GitHub
bullfrogsec/bullfrog v0.8.4 removed
Block unauthorized outbound traffic (egress) in your Github workflows
23 versions - Latest release: 8 months ago - 110 stars on GitHub
lnavarrocarter/actions-rules-repository 1.1.4 removed
Add rules repository labels to issues and pull requests.
7 versions - Latest release: over 2 years ago - 1 dependent repositories - 1 stars on GitHub
Top 0.6% on github actions
gradle/wrapper-validation-action v3.5.0 removed
Validates Gradle Wrapper JAR Files
25 versions - Latest release: over 1 year ago - 11,383 dependent repositories - 277 stars on GitHub
Top 8.8% on github actions
zricethezav/gitleaks-action v2.3.9 removed 💰
run gitleaks on push and pull-request events
41 versions - Latest release: 9 months ago - 397 stars on GitHub
Top 3.5% on github actions
stackrox/kube-linter-action v1.0.7 removed
Scan directory or file with kube-linter
11 versions - Latest release: 8 months ago - 65 dependent repositories - 38 stars on GitHub
Top 8.1% on github actions
SecureStackCo/actions-exposure v0.1.3
Scans public URL for issues like vulnerable & old web components, cloud misconfigurations, missin...
4 versions - Latest release: almost 4 years ago - 6 dependent repositories - 21 stars on GitHub
Staffbase/npm-audit-fix-action v4.0.10 removed
Run `npm audit fix` and create a pull request
58 versions - Latest release: over 3 years ago - 3 dependent repositories - 0 stars on GitHub
hashicorp/setup-signore v3.0.0 removed
setup-signore downloads, installs, and configures the signore signing service client
10 versions - Latest release: over 1 year ago - 9 dependent repositories - 0 stars on GitHub
Top 9.9% on github actions
SecureStackCo/actions-secrets v0.1.3 removed
Scan your source code for sensitive data like API keys, passwords, server host strings, config an...
5 versions - Latest release: almost 4 years ago - 13 dependent repositories - 22 stars on GitHub
cfy9/trivy-action v0.0.7 removed
GitHub action to scan docker images for vulnerability issues using trivy.
7 versions - Latest release: 10 months ago - 1 stars on GitHub
Top 2.6% on github actions
symfonycorp/security-checker-action v5 removed
Checks composer.json for known vulnerabilities in your package dependencies
5 versions - Latest release: about 3 years ago - 162 dependent repositories - 138 stars on GitHub
Top 4.3% on github actions
tjenkinson/gh-action-auto-merge-dependency-updates v1.4.2 removed
Automatically merge a PR that only contains dependency updates, based on some rules.
24 versions - Latest release: almost 2 years ago - 157 dependent repositories - 14 stars on GitHub
godaddy/tartufo-action 4.1.0 removed
Runs scan-local-repo with default options
9 versions - Latest release: almost 3 years ago - 4 dependent repositories - 7 stars on GitHub
geritol/write-guard v0.4.0 removed
Enforce file level write access for monorepos
6 versions - Latest release: almost 4 years ago - 1 dependent repositories - 8 stars on GitHub
Top 7.2% on github actions
jbergstroem/hadolint-gh-action v1.12.2 removed
A stable, well-tested, highly configurable way of checking your Dockerfile(s) with Hadolint
20 versions - Latest release: almost 2 years ago - 74 dependent repositories - 12 stars on GitHub
chaitin/veinmind-action v1.0.5 removed
Scan images for security issues with veinmind-tools
6 versions - Latest release: almost 3 years ago - 2 dependent repositories - 8 stars on GitHub
saucelabs/sauce-security-action v0.3.0 removed
A GitHub action to run security scans on your applications.
3 versions - Latest release: over 4 years ago - 3 stars on GitHub
Top 0.9% on github actions
actions-rs/audit-check v1.2.0 removed 💰
Run cargo audit and check for security advisories
4 versions - Latest release: over 5 years ago - 2,306 dependent repositories - 157 stars on GitHub
bashofmann/neuvector-image-scan-action removed
Scans a container image for vulnerabilities with [NeuVector](https://neuvector.com)
Latest release: 8 months ago - 1 stars on GitHub
sammcj/github-app-installation-token v2.17.0 removed 💰
Run a GitHub Action as a GitHub App Installation instead of using secrets.GITHUB_TOKEN or a perso...
131 versions - Latest release: over 1 year ago - 2 dependent repositories - 4 stars on GitHub
Top 5.5% on github actions
andrewmcodes/bundler-audit-action v0.1.0 removed 💰
GitHub Action for running bundler-audit
2 versions - Latest release: over 5 years ago - 19 dependent repositories - 14 stars on GitHub
rogeruiz/repasar v1.0.0 removed
Run git-verify-commit command on the latest SHA
1 version - Latest release: about 3 years ago - 1 dependent repositories - 1 stars on GitHub
Top 9.1% on github actions
nowsecure/nowsecure-sbom-action v3.0.0 removed
Generate a Mobile SBOM for an application and submit to the Dependency submission API
8 versions - Latest release: over 1 year ago - 9 dependent repositories - 9 stars on GitHub
Top 4.1% on github actions
apisec-inc/apisec-run-scan v1.0.7 removed
Continuous, automated, comprehensive API Security Testing
8 versions - Latest release: over 2 years ago - 114 dependent repositories - 23 stars on GitHub
Top 2.7% on github actions
microsoft/security-devops-action v1.12.0 removed
Run security analyzers.
14 versions - Latest release: about 1 year ago - 42 dependent repositories - 107 stars on GitHub
Top 2.2% on github actions
bridgecrewio/bridgecrew-action v1.2343.0 removed
Find and fix security and compliance issues in infrastructure as code, open source packages, cont...
1,100 versions - Latest release: about 2 years ago - 114 dependent repositories - 71 stars on GitHub
nuwaycloud/trivy-action v0.0.3 removed
GitHub action to scan docker images for vulnerability issues using trivy.
3 versions - Latest release: about 1 year ago - 1 stars on GitHub
druidfi/security-checker-action v1 removed
Checks composer.json for known available security updates in your package dependencies
1 version - Latest release: over 3 years ago - 1 dependent repositories - 0 stars on GitHub
venura9/manage-nsg v1.2 removed
Add/Remove NSG Rules using the public IP of the hosted runner
6 versions - Latest release: over 5 years ago - 3 dependent repositories - 4 stars on GitHub
Top 0.3% on github actions
aquasecurity/trivy-action 0.29.0 removed
Scans container images for vulnerabilities with Trivy
68 versions - Latest release: about 1 year ago - 3,327 dependent repositories - 832 stars on GitHub
martins-vds/export-secrets-action v1
Export secrets to CSV file.
1 version - Latest release: over 2 years ago - 1 dependent repositories - 0 stars on GitHub
yu-iskw/action-terrascan v1.2.2
TODO: 🐶 Run terrascan with reviewdog on pull requests to improve code review experience.
15 versions - Latest release: over 3 years ago - 0 stars on GitHub
Top 1.1% on github actions
gitleaks/gitleaks-action v2.3.7 removed
run gitleaks on push and pull-request events
39 versions - Latest release: about 1 year ago - 211 dependent repositories - 243 stars on GitHub
trendmicro/cloudone-container-security-github-action 1.0.11 removed
Scan container images with Vision One Container Security
12 versions - Latest release: about 1 year ago - 7 stars on GitHub
recognizegroup/recognize-vulnerability-report-action v1.1.0 removed
Create a report of the vulnerabilities that are found and add it as a comment to a pull request.
3 versions - Latest release: about 3 years ago - 1 dependent repositories - 0 stars on GitHub
Checkmarx/dustilock v1.2.0 removed
DustiLock is a tool to find which of your dependencies is susceptible to Dependency Confusion attack
4 versions - Latest release: about 4 years ago - 28 stars on GitHub
Pwd9000-ML/azure-vm-password-rotate v1.1.0 removed
Rotate AZURE virtual machines local administrator Passwords, using AZURE key vault
4 versions - Latest release: almost 4 years ago - 1 dependent repositories - 3 stars on GitHub
Top 0.3% on github actions
google-github-actions/auth v2.1.6 removed
Authenticate to Google Cloud from GitHub Actions via Workload Identity Federation or service acco...
37 versions - Latest release: over 1 year ago - 4,745 dependent repositories - 835 stars on GitHub
Top 8.5% on github actions
federacy/scan-action 0.1.5 removed
SAST and Dependency Scanning
6 versions - Latest release: over 2 years ago - 7 dependent repositories - 11 stars on GitHub
timmeinerzhagen/dependabot-sha-comment-action v1.0.0 removed
Update version comment for SHA pin of GitHub Actions on Dependabot update.
7 versions - Latest release: over 3 years ago - 2 stars on GitHub
Top 8.5% on github actions
accurics/accurics-action v2.0.3 removed
The Accurics GitHub Action scans IaC (Infrastructure as Code) to help identify vulnerabilities pr...
44 versions - Latest release: about 3 years ago - 3 dependent repositories - 12 stars on GitHub
grolston/guard-action 1.0 removed
Guard ShiftLeft
1 version - Latest release: over 3 years ago - 1 dependent repositories - 2 stars on GitHub
clj-holmes/clj-holmes-action main removed
Executes clj-holmes security scan in clojure/clojurescript projects.
1 version - Latest release: over 3 years ago - 48 dependent repositories - 4 stars on GitHub
gioragutt/scan-unverified-actions v1 removed
Scans your Github Actions Workflows for unverified actions
1 version - Latest release: over 4 years ago - 1 dependent repositories - 1 stars on GitHub
nwestfall/netsparkerscanrunner 0.1.9 removed
Run Netsparker Scans and get back test results
5 versions - Latest release: almost 5 years ago - 4 stars on GitHub
jhutchings1/spdx-to-dependency-graph-action v0.0.2 removed
Upload SPDX SBOM files to the dependency graph's dependency submission API
2 versions - Latest release: about 3 years ago - 6 dependent repositories - 10 stars on GitHub
marcuslindblom/security-headers v1.2.0 removed 💰
Quickly and easily assess the security of your HTTP response headers
4 versions - Latest release: over 4 years ago - 1 dependent repositories - 8 stars on GitHub
malice-labs/fork-sentry 1.0 removed
Detect and alert on suspicious forks of your repository
1 version - Latest release: almost 4 years ago - 2 stars on GitHub
Top 6.2% on github actions
apisec-inc/ethicalcheck-action v1.0.6 removed
Free & Instant API Penetration Testing Service
9 versions - Latest release: about 3 years ago - 33 dependent repositories - 28 stars on GitHub
magmanu/github-workflow-security-scanner v0.1.0 removed
A GitHub Action that performs static analysis on your workflows
1 version - Latest release: over 2 years ago - 0 stars on GitHub
ncino/quack-scan v1.0.3 removed
Run static code dependency scan using Black Duck Synopsys scan for NPM and PIP using Synopsys 6.0.
7 versions - Latest release: over 4 years ago - 2 stars on GitHub
kubeshop/monokle-action v0.3.2 removed
Monokle Action analyzes your Kubernetes resources to quickly find misconfigurations.
9 versions - Latest release: about 2 years ago - 1 dependent repositories - 5 stars on GitHub
kahu-app/github-action v0.3.1 removed
Dependency security check
8 versions - Latest release: over 2 years ago - 0 stars on GitHub