Find GitHub Actions you can actually trust
We score 1,136 actions across security, maintenance, popularity and reliability — 474 of them are abandoned.
Top rated actions
The highest composite scores across every category.
A composite GitHub Action that turns conventional commits into a draft release PR, tags the PR on merge, and stages publishing to npm via OIDC trusted publishing.
A fence keeps things out, but also in. This project is still in early, and active development.
Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 8 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed.
GitHub Action to run Terraform plan and add a comment with the changes.
GitHub Action to build and push Docker images with Buildx
GitHub Action to set up Docker Buildx
Recently flagged: abandoned but still popular
Mutable tags plus unmaintained code are a supply-chain risk — the same conditions behind the tj-actions/changed-files compromise.
📊 An infographics generator with 30+ plugins and 300+ options to display stats about your GitHub account and render them as SVG, Markdown, PDF or JSON!
An easy to use blogging platform, with enhanced support for Jupyter Notebooks.
Automated API Testing and Quality Assurance
Open source alternative to Percy, Chromatic, Applitools.
An Action to create releases via the GitHub Release API
AutoPR autonomously wrote pull requests in response to issues
How scoring works
Every action gets a 0–100 score from four weighted dimensions.
OpenSSF Scorecard, known advisories, SECURITY.md and release immutability.
Commit recency, release cadence and whether anyone still answers issues.
Stars and contributor count, log-normalized so giants don't drown the field.
Semver compliance, major-tag convention and breaking-change frequency.
Browse by category
Ranked lists for every corner of the Actions ecosystem.
Run AI-assisted review, generation and agent workflows in CI.
Caching & ArtifactsCache dependencies and share build artifacts between jobs.
Code Quality & LintingLint, format and review code automatically.
DeploymentActions that deploy code to clouds, servers, registries and platforms.
Docker & ContainersBuild, tag, scan and push container images.
NotificationsSend build and deploy notifications to chat and issue trackers.
Release & VersioningAutomate releases, changelogs, tags and package publishing.
Repo AutomationLabel, triage, greet, merge and manage issues and pull requests.
SecurityScan code, dependencies, secrets and workflows for vulnerabilities.
Setup & EnvironmentsInstall languages, runtimes and toolchains on runners.
Testing & CoverageRun test suites, report results and track coverage.
UtilitiesGeneral-purpose workflow building blocks: checkout, scripts, file ops.