ActionRank

Security GitHub Actions

Scan code, dependencies, secrets and workflows for vulnerabilities.

101 actions

  1. B
    Fence

    A fence keeps things out, but also in. This project is still in early, and active development.

    83
  2. B
    Shai-Hulud 2.0 Detector

    GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.

    81
  3. B
    Pipelock Agent Security Scan

    Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.

    80
  4. B
    Harden-Runner

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

    79
  5. B
    Anchore Container Scan

    Anchore container analysis and scan provided as a GitHub Action

    79
  6. B
    "Configure AWS Credentials" Action for GitHub Actions

    Configure AWS credential environment variables for use in other GitHub Actions.

    78
  7. B
    Lightning Flow Scan

    Lightning Flow Scanner is an open-source Salesforce CLI plugin, VS Code extension, and GitHub Action for analysing and optimising Salesforce Flows. It scans metadata against 20+ community-driven rules — hardcoded IDs, missing fault paths, inefficient DML, recursion risks, and more. Includes auto-fixes, configurable rules, and CI/CD integration

    78
  8. B
    Skylos - Python SAST, Dead Code Detection & PR Gate

    Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/

    77
  9. B
    zizmor-action

    Run zizmor from GitHub Actions!

    76
  10. B
    OSSF Scorecard action

    Official GitHub Action for OpenSSF Scorecard.

    75
  11. B
    node9 Agent Security

    The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.

    75
  12. B
    Codex Guard PR Quality Gate

    Quality gate for AI/Codex-generated pull requests: blocks TODO leftovers, leaked secrets, sloppy commits and red CI before they reach main.

    74
  13. B
    Test LLM outputs

    The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.

    74
  14. B
    Provenance downgrade check

    Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status

    74
  15. B
    Aguara Security Scanner

    The open source security engine for AI agent and supply-chain trust.

    73
  16. B
    Agents Shipgate

    The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.

    73
  17. B
    actions--access-token

    Get rid of personal access tokens (PAT) and credential management, use temporary GitHub Application access tokens instead!

    73
  18. B
    compose-lint

    Security-focused linter for Docker Compose files. Catches dangerous misconfigurations before they reach production. Grounded in OWASP and CIS Docker Benchmark.

    73
  19. B
    gh-action-sigstore-python

    A GitHub Action for sigstore-python

    73
  20. B
    AI Surface Check

    Find and govern AI attack surfaces in application code at PR time. Free, OSS, runs offline.

    72
  21. B
    AWS Secrets Manager GitHub Action
    72
  22. B
    Aletheore

    Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.

    72
  23. B
    Ensure SHA Pinned Actions

    A Github Action to ensure that actions are pinned to full length commit SHAs

    71
  24. B
    Repo Publication Audit

    Dependency-free preflight checks for repositories before making them public

    70
  25. B
    pinact

    GitHub Actions to pin GitHub Actions by pinact

    70
  26. C
    Run tfsec with reviewdog

    Run tfsec with reviewdog on pull requests to enforce security best practices

    69
  27. C
    Gitleaks

    Protect your secrets using Gitleaks-Action

    69
  28. C
    RepoCare repository health

    A local-first repository health scanner with actionable scoring for open-source maintainers.

    68
  29. C
    Aqua Security Trivy

    Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

    68
  30. C
    Qodana Scan

    ⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle

    68
  31. C
    pypi-publish

    The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish

    68
  32. C
    Container Scan

    GitHub Action to check for vulnerabilities in your container image

    67
  33. C
    Bullfrog Secure Runner

    Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows

    67
  34. C
    HashiCorp Vault

    A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.

    66
  35. C
    Import Code-Signing Certificates

    GitHub Action for Importing Code-signing Certificates into a Keychain

    66
  36. C
    osv-scanner
    66
  37. C
    Load secrets from 1Password

    Load secrets from 1Password into your GitHub Actions jobs

    66
  38. C
    Download Apple Provisioning Profiles

    Github Action for downloading provisioning profiles from Apple AppStore Connect

    66
  39. C
    Frogbot by JFrog

    🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖

    65
  40. C
    Docker Scout

    Docker Scout GitHub Action

    65
  41. C
    CodeQL: Stub

    Actions for running CodeQL analysis

    65
  42. C
    cargo-deny

    ❌ GitHub Action for cargo-deny 🦀

    65
  43. C
    Snyk

    A set of GitHub actions for checking your projects for vulnerabilities.

    64
  44. C
    Cimon by Cycode

    Runtime Security Solution for your CI/CD Pipeline

    64
  45. C
    1Password CLI

    Install 1Password CLI into your GitHub Actions jobs.

    64
  46. C
    Authenticate to Google Cloud

    A GitHub Action for authenticating to Google Cloud.

    64
  47. C
    GitGuardian Shield Action

    GitGuardian Shield GitHub Action - Find exposed credentials in your commits

    63
  48. C
    Runseal - Supply Chain Security Action

    Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.

    63
  49. C
    Import GPG

    GitHub Action to import a GPG key

    63
  50. C
    Envilder GitHub Action

    One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift.

    62