Ecosyste.ms: Packages

An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

github actions "security" keyword

adanalvarez/openai-security-review v0.2.0
A GitHub Action that reviews the modified files and comments with security recommendations
4 versions - Latest release: over 1 year ago - 3 stars on GitHub
CycodeLabs/cimon-action v0.9.4
Runtime Security Solution for your CI/CD Pipeline
26 versions - Latest release: 7 months ago - 1 dependent repositories - 59 stars on GitHub
Top 7.0% on github actions
hahwul/deadfinder 1.3.4 💰
Find dead-links (broken links)
14 versions - Latest release: 4 months ago - 2 dependent repositories - 89 stars on GitHub
Top 3.2% on github actions
tonybaloney/pycharm-security 1.29.0 💰
Scan your Python Code for security issues
51 versions - Latest release: 10 months ago - 23 dependent repositories - 315 stars on GitHub
Top 9.9% on github actions
SecureStackCo/actions-secrets v0.1.3
Scan your source code for sensitive data like API keys, passwords, server host strings, config an...
5 versions - Latest release: over 2 years ago - 13 dependent repositories - 22 stars on GitHub
Top 4.3% on github actions
tjenkinson/gh-action-auto-merge-dependency-updates v1.4.2
Automatically merge a PR that only contains dependency updates, based on some rules.
24 versions - Latest release: about 2 months ago - 157 dependent repositories - 14 stars on GitHub
actions-rust-lang/audit v1.1.14
Audit Rust dependencies with cargo audit and the RustSec Advisory DB
21 versions - Latest release: 3 months ago - 26 dependent repositories - 5 stars on GitHub
Top 6.5% on github actions
aquasecurity/tracee-action v0.4.0-stop
Protect your GitHub Actions pipelines with eBPF profiling
8 versions - Latest release: 9 months ago - 4 dependent repositories - 50 stars on GitHub
NeuraLegion/run-scan v1
Run a Nexploit scan right in GitHub Action
3 versions - Latest release: about 4 years ago - 26 dependent repositories - 2 stars on GitHub
rcowsill/workflow-scan-action v3.0.0
Scan GitHub Actions workflow files with CodeQL
4 versions - Latest release: 4 months ago - 2 dependent repositories - 2 stars on GitHub
Top 2.9% on github actions
oke-py/npm-audit-action v2.4.4
run npm audit
32 versions - Latest release: over 1 year ago - 88 dependent repositories - 34 stars on GitHub
martins-vds/export-secrets-action v1
Export secrets to CSV file.
1 version - Latest release: about 1 year ago - 1 dependent repositories - 0 stars on GitHub
Top 4.3% on github actions
reload/github-security-jira v1.5.0
Synchronize the current repo alert state with JIRA and creates tickets accordingly.
8 versions - Latest release: 6 months ago - 13 dependent repositories - 48 stars on GitHub
Top 2.6% on github actions
symfonycorp/security-checker-action v5
Checks composer.json for known vulnerabilities in your package dependencies
5 versions - Latest release: over 1 year ago - 162 dependent repositories - 138 stars on GitHub
InstaCode/lockdown v1.0.0
Restrict build runs to specific users.
3 versions - Latest release: about 4 years ago - 0 stars on GitHub
Staffbase/npm-audit-fix-action v4.0.10
Run `npm audit fix` and create a pull request
58 versions - Latest release: over 1 year ago - 3 dependent repositories - 0 stars on GitHub
Top 6.7% on github actions
RIGS-IT/xanitizer-action v1.0.1
GitHub action to download and install Xanitizer, and to run a Xanitizer security analysis in a Gi...
3 versions - Latest release: over 3 years ago - 76 dependent repositories - 8 stars on GitHub
Top 4.7% on github actions
djdefi/gitavscan 19 💰
Anti Virus scan for malicious files in a Git repository
19 versions - Latest release: 2 months ago - 68 dependent repositories - 35 stars on GitHub
Checkmarx/dustilock v1.2.0
DustiLock is a tool to find which of your dependencies is susceptible to Dependency Confusion attack
4 versions - Latest release: over 2 years ago - 28 stars on GitHub
recognizegroup/recognize-vulnerability-report-action v1.1.0
Create a report of the vulnerabilities that are found and add it as a comment to a pull request.
3 versions - Latest release: over 1 year ago - 1 dependent repositories - 0 stars on GitHub
Top 0.6% on github actions
gradle/wrapper-validation-action v3.3.2 removed
Validates Gradle Wrapper JAR Files
21 versions - Latest release: about 1 month ago - 11,383 dependent repositories - 253 stars on GitHub
Top 5.1% on github actions
redhat-actions/crda v1.0.0
Analyse vulnerabilities in application dependencies
5 versions - Latest release: over 2 years ago - 48 dependent repositories - 14 stars on GitHub
clj-holmes/clj-holmes-action main
Executes clj-holmes security scan in clojure/clojurescript projects.
1 version - Latest release: almost 2 years ago - 48 dependent repositories - 4 stars on GitHub
SeisoLLC/goat v2024.04.04
Apply Seiso's standard testing
43 versions - Latest release: 28 days ago - 12 stars on GitHub
godaddy/tartufo-action 4.1.0
Runs scan-local-repo with default options
9 versions - Latest release: about 1 year ago - 4 dependent repositories - 7 stars on GitHub
clj-holmes/clj-watson-action main
Executes clj-watson dependency security scan in clojure/clojurescript projects.
1 version - Latest release: almost 2 years ago - 15 dependent repositories - 2 stars on GitHub
Top 9.9% on github actions
Nekmo/pip-rating v0.2.2
Run pip-rating on the project to get the requirements rating based on criteria like freshness, po...
4 versions - Latest release: 8 months ago - 10 dependent repositories - 27 stars on GitHub
DopplerHQ/secrets-fetch-action v1.2.0
Fetch Doppler secrets for a specific Project and Config
6 versions - Latest release: 2 months ago - 9 stars on GitHub
Top 8.6% on github actions
DopplerHQ/cli-action v3
Install the Doppler CLI into your PATH
3 versions - Latest release: 4 months ago - 1 dependent repositories - 39 stars on GitHub
UlisesGascon/openssf-scorecard-monitor v1.0.1
Monitor OpenSSF Scorecard Evolution over time
9 versions - Latest release: over 1 year ago - 3 dependent repositories - 19 stars on GitHub
Top 4.6% on github actions
sigstore/gh-action-sigstore-python v2.1.1
Use sigstore-python to sign Python packages
26 versions - Latest release: 6 months ago - 143 dependent repositories - 32 stars on GitHub
Top 7.2% on github actions
jbergstroem/hadolint-gh-action v1.12.2
A stable, well-tested, highly configurable way of checking your Dockerfile(s) with Hadolint
20 versions - Latest release: 4 months ago - 74 dependent repositories - 12 stars on GitHub
Top 3.8% on github actions
pypa/gh-action-pip-audit v1.0.8 💰
Use pip-audit to scan Python dependencies for known vulnerabilities
15 versions - Latest release: about 1 year ago - 131 dependent repositories - 51 stars on GitHub
hashicorp/setup-signore v2.1.0
setup-signore downloads, installs, and configures the signore signing service client
9 versions - Latest release: about 1 year ago - 9 dependent repositories - 0 stars on GitHub
Top 3.5% on github actions
stackrox/kube-linter-action v1.0.5
Scan directory or file with kube-linter
9 versions - Latest release: 3 months ago - 65 dependent repositories - 29 stars on GitHub
xen0l/iam-lint v2
Github Action to lint AWS IAM policy document files with parliament from DUo Labs
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 33 stars on GitHub
hahwul/zest-env v1.1.4 💰
Zest CLI in Github action
7 versions - Latest release: 23 days ago - 8 stars on GitHub
Top 2.2% on github actions
bridgecrewio/bridgecrew-action v1.2343.0
Find and fix security and compliance issues in infrastructure as code, open source packages, cont...
1,100 versions - Latest release: 6 months ago - 114 dependent repositories - 71 stars on GitHub
secrethub/actions v0.2.1
Load secrets into your GitHub workflows
3 versions - Latest release: over 3 years ago - 46 stars on GitHub
SecureStackCo/actions-sbom v0.2.0
Create a Software Bill of Materials (SBOM) with SecureStack
4 versions - Latest release: almost 2 years ago - 1 dependent repositories - 19 stars on GitHub
Top 3.4% on github actions
zaproxy/action-api-scan v0.7.0 💰
Scans the web application with the ZAP API Scan
9 versions - Latest release: about 2 months ago - 70 dependent repositories - 37 stars on GitHub
xen0l/dlint-check 0.10.1
Github Action to lint Python code with dlint from Duo Labs
2 versions - Latest release: over 4 years ago - 1 dependent repositories - 2 stars on GitHub
Traceableai/ast-action 0.0.5
GitHub action for Traceable Active Security Testing
6 versions - Latest release: about 1 year ago - 1 dependent repositories - 5 stars on GitHub
Top 5.0% on github actions
jpetrucciani/bandit-check 1.7.8 💰
GitHub action to lint your python code with bandit
10 versions - Latest release: 3 months ago - 84 dependent repositories - 12 stars on GitHub
HCL-TECH-SOFTWARE/appscan-sast-action v1.0.4
Scan for security issues in code
5 versions - Latest release: about 2 months ago - 7 dependent repositories - 3 stars on GitHub
embold/github-action-docker v0.2
Embold design and code quality scanning engine
2 versions - Latest release: over 2 years ago - 1 dependent repositories - 2 stars on GitHub
grolston/guard-action 1.0
Guard ShiftLeft
1 version - Latest release: almost 2 years ago - 1 dependent repositories - 2 stars on GitHub
kahu-app/github-action v0.3.1
Dependency security check
8 versions - Latest release: 10 months ago - 0 stars on GitHub
hoeg/semgrep-report v1.0.2
Report Semgrep findimgs to PRs with suggested changes
5 versions - Latest release: 11 months ago - 0 stars on GitHub
Top 9.1% on github actions
nowsecure/nowsecure-sbom-action v2.0.0
Generate a Mobile SBOM for an application and submit to the Dependency submission API
6 versions - Latest release: over 1 year ago - 9 dependent repositories - 7 stars on GitHub
Top 7.9% on github actions
victoriadrake/hugo-remote v1.1.1 💰
🚀 Build and deploy a Hugo site to a remote repository with latest extended Hugo.
5 versions - Latest release: over 3 years ago - 1 dependent repositories - 59 stars on GitHub
Top 2.5% on github actions
kitabisa/sonarqube-action v1.2.1
Scan your code with SonarQube Scanner to detect bugs, vulnerabilities and code smells in more tha...
11 versions - Latest release: 8 months ago - 59 dependent repositories - 122 stars on GitHub
piraces/kube-score-ga v0.1.3 💰
Uses the kube-score analysis tool to perform static code analysis of your Kubernetes object defin...
4 versions - Latest release: over 1 year ago - 5 dependent repositories - 9 stars on GitHub
Top 5.5% on github actions
andrewmcodes/bundler-audit-action v0.1.0 💰
GitHub Action for running bundler-audit
2 versions - Latest release: almost 4 years ago - 19 dependent repositories - 14 stars on GitHub
alessiodionisi/setup-age-action v1.3.0 💰
Setup age and add it to the PATH
5 versions - Latest release: 3 months ago - 1 dependent repositories - 7 stars on GitHub
silverhack/monkey365 v0.91.2-beta
Install and run PSScriptAnalyzer
5 versions - Latest release: 5 months ago - 630 stars on GitHub
Top 6.5% on github actions
Contrast-Security-OSS/contrastscan-action v3.0.1
Perform SAST analysis of a project
10 versions - Latest release: 4 months ago - 34 dependent repositories - 19 stars on GitHub
dentarg/gem-compare v1.3.2 removed 💰
Compare different gem versions
9 versions - Latest release: 6 months ago - 4 dependent repositories - 1 stars on GitHub
kattecon/gh-app-access-token-gen v1.0.0
Generates a GitHub Access Token for a Github App based upon specific inputs.
2 versions - Latest release: about 1 year ago - 1 dependent repositories - 1 stars on GitHub
f-actions/opentype-sanitizer v3.0.0
A GitHub Action for opentype-sanitizer testing of font artifacts
8 versions - Latest release: 3 months ago - 1 dependent repositories - 6 stars on GitHub
Top 1.1% on github actions
gitleaks/gitleaks-action v2.3.4 removed
run gitleaks on push and pull-request events
36 versions - Latest release: 3 months ago - 211 dependent repositories - 243 stars on GitHub
sudo-bot/action-docker-sign latest
Sign docker images
1 version - Latest release: almost 3 years ago - 10 dependent repositories - 6 stars on GitHub
NeuraLegion/wait-for v1
Run a Nexploit scan right in GitHub Action
1 version - Latest release: about 4 years ago - 0 stars on GitHub
nwestfall/netsparkerscanrunner 0.1.9 removed
Run Netsparker Scans and get back test results
5 versions - Latest release: over 3 years ago - 4 stars on GitHub
jhutchings1/spdx-to-dependency-graph-action v0.0.2 removed
Upload SPDX SBOM files to the dependency graph's dependency submission API
2 versions - Latest release: over 1 year ago - 6 dependent repositories - 10 stars on GitHub
reposaur/repo-audit-action v0.1.0 removed
Audit your organization's repositories using Reposaur.
1 version - Latest release: about 2 years ago - 1 stars on GitHub
Top 2.6% on github actions
triat/terraform-security-scan v3.1.0 removed
Scan your terraform code with tfsec
21 versions - Latest release: 9 months ago - 54 dependent repositories - 105 stars on GitHub
Top 0.9% on github actions
actions-rs/audit-check v1.2.0 removed 💰
Run cargo audit and check for security advisories
4 versions - Latest release: about 4 years ago - 2,306 dependent repositories - 157 stars on GitHub
marcuslindblom/security-headers v1.2.0 removed 💰
Quickly and easily assess the security of your HTTP response headers
4 versions - Latest release: almost 3 years ago - 1 dependent repositories - 8 stars on GitHub
GrantBirki/auditor-action-core v3.0.1 removed
The Auditor Action's Core
21 versions - Latest release: 2 months ago - 1 dependent repositories - 0 stars on GitHub
Top 3.9% on github actions
step-security/wait-for-secrets v1.1.0 removed
Publish from GitHub Actions using multi-factor authentication
8 versions - Latest release: over 1 year ago - 16 dependent repositories - 260 stars on GitHub
gabrielrufino/mongodump-action v1.0.2 removed 💰
GitHub Action for creating a binary export of a database's contents
5 versions - Latest release: 5 months ago - 1 dependent repositories - 0 stars on GitHub
Top 6.6% on github actions
ScribeMD/rootless-docker 0.2.2 removed
Run Docker in Rootless Mode to Prevent Permission Errors
11 versions - Latest release: over 1 year ago - 17 dependent repositories - 21 stars on GitHub
malice-labs/fork-sentry 1.0 removed
Detect and alert on suspicious forks of your repository
1 version - Latest release: over 2 years ago - 2 stars on GitHub
Top 0.9% on github actions
bridgecrewio/checkov-action v12.2659.0
Run Checkov against infrastructure as code, open source packages, container images, and CI/CD con...
1,194 versions - Latest release: 4 months ago - 507 dependent repositories - 190 stars on GitHub
Top 6.2% on github actions
apisec-inc/ethicalcheck-action v1.0.6 removed
Free & Instant API Penetration Testing Service
9 versions - Latest release: over 1 year ago - 33 dependent repositories - 28 stars on GitHub
magmanu/github-workflow-security-scanner v0.1.0 removed
A GitHub Action that performs static analysis on your workflows
1 version - Latest release: about 1 year ago - 0 stars on GitHub
ncino/quack-scan latest removed
Run static code dependency scan using Black Duck Synopsys scan for NPM and PIP using Synopsys 6.0.
7 versions - Latest release: about 3 years ago - 2 stars on GitHub