Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
101 actions
- BActive★ 15114 days ago83Fenceopenai/fence
A fence keeps things out, but also in. This project is still in early, and active development.
- BActive★ 1501 months ago81Shai-Hulud 2.0 Detectorgensecaihq/Shai-Hulud-2.0-Detector
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
- BActive★ 872today80Pipelock Agent Security ScanluckyPipewrench/pipelock
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
- BActive★ 1.3k17 days ago79Harden-Runnerstep-security/harden-runner
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
- BActive★ 2875 days ago79Anchore Container Scananchore/scan-action
Anchore container analysis and scan provided as a GitHub Action
- BActive★ 3kyesterday78"Configure AWS Credentials" Action for GitHub Actionsaws-actions/configure-aws-credentials
Configure AWS credential environment variables for use in other GitHub Actions.
- BActive★ 17417 days ago78Lightning Flow ScanFlow-Scanner/lightning-flow-scanner
Lightning Flow Scanner is an open-source Salesforce CLI plugin, VS Code extension, and GitHub Action for analysing and optimising Salesforce Flows. It scans metadata against 20+ community-driven rules — hardcoded IDs, missing fault paths, inefficient DML, recursion risks, and more. Includes auto-fixes, configurable rules, and CI/CD integration
- BActive★ 802yesterday77Skylos - Python SAST, Dead Code Detection & PR Gateduriantaco/skylos
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
- BActive★ 1627 days ago76zizmor-actionzizmorcore/zizmor-action
Run zizmor from GitHub Actions!
- BActive★ 4171 months ago75OSSF Scorecard actionossf/scorecard-action
Official GitHub Action for OpenSSF Scorecard.
- BActive★ 2122 days ago75node9 Agent Securitynode9-ai/node9-proxy
The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for autonomous AI agents.
- BActive★ 14116 days ago74Codex Guard PR Quality GateAkimiya-z/codex-guard
Quality gate for AI/Codex-generated pull requests: blocks TODO leftovers, leaked secrets, sloppy commits and red CI before they reach main.
- BActive★ 724 days ago74Test LLM outputspromptfoo/promptfoo-action
The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.
- BActive★ 3082 days ago74Provenance downgrade checkdanielroe/provenance-action
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
- BActive★ 886 days ago73Aguara Security Scannergaragon/aguara
The open source security engine for AI agent and supply-chain trust.
- BActive★ 892 days ago73Agents ShipgateThreeMoonsLab/agents-shipgate
The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.
- BActive★ 2159 days ago73actions--access-tokenqoomon/actions--access-token
Get rid of personal access tokens (PAT) and credential management, use temporary GitHub Application access tokens instead!
- BActive★ 563 days ago73compose-linttmatens/compose-lint
Security-focused linter for Docker Compose files. Catches dangerous misconfigurations before they reach production. Grounded in OWASP and CIS Docker Benchmark.
- BActive★ 713 days ago73gh-action-sigstore-pythonsigstore/gh-action-sigstore-python
A GitHub Action for sigstore-python
- BActive★ 12621 days ago72AI Surface Checkapisec-inc/AI-Surface
Find and govern AI attack surfaces in application code at PR time. Free, OSS, runs offline.
- BActive★ 1937 days ago72AWS Secrets Manager GitHub Actionaws-actions/aws-secretsmanager-get-secrets
- BActive★ 1582 days ago72AletheoreAletheore/Aletheore
Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
- BActive★ 5511 days ago71Ensure SHA Pinned Actionszgosalvez/github-actions-ensure-sha-pinned-actions
A Github Action to ensure that actions are pinned to full length commit SHAs
- BActive★ 971 months ago70Repo Publication Auditduy90utc528/repo-publication-audit
Dependency-free preflight checks for repositories before making them public
- BActive★ 772 days ago70pinactsuzuki-shunsuke/pinact-action
GitHub Actions to pin GitHub Actions by pinact
- CActive★ 762 days ago69Run tfsec with reviewdogreviewdog/action-tfsec
Run tfsec with reviewdog on pull requests to enforce security best practices
- CActive★ 6451 months ago69Gitleaksgitleaks/gitleaks-action
Protect your secrets using Gitleaks-Action
- CActive★ 1001 months ago68RepoCare repository healthlstsavr/repocare
A local-first repository health scanner with actionable scoring for open-source maintainers.
- CActive★ 1.4k1 months ago68Aqua Security Trivyaquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
- CActive★ 3114 days ago68Qodana ScanJetBrains/qodana-action
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
- CActive★ 1.2k1 months ago68pypi-publishpypa/gh-action-pypi-publish
The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish
- CActive★ 752 months ago67Container Scancrazy-max/ghaction-container-scan
GitHub Action to check for vulnerabilities in your container image
- CActive★ 12921 days ago67Bullfrog Secure Runnerbullfrogsec/bullfrog
Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows
- CActive★ 51319 days ago66HashiCorp Vaulthashicorp/vault-action
A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.
- CActive★ 2812 days ago66Import Code-Signing CertificatesApple-Actions/import-codesign-certs
GitHub Action for Importing Code-signing Certificates into a Keychain
- CActive★ 962 days ago66osv-scannergoogle/osv-scanner-action
- CActive★ 3406 days ago66Load secrets from 1Password1Password/load-secrets-action
Load secrets from 1Password into your GitHub Actions jobs
- CActive★ 9713 days ago66Download Apple Provisioning ProfilesApple-Actions/download-provisioning-profiles
Github Action for downloading provisioning profiles from Apple AppStore Connect
- CActive★ 3727 days ago65Frogbot by JFrogjfrog/frogbot
🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖
- CActive★ 1411 months ago65Docker Scoutdocker/scout-action
Docker Scout GitHub Action
- CActive★ 1.6kyesterday65CodeQL: Stubgithub/codeql-action
Actions for running CodeQL analysis
- CActive★ 1941 months ago65cargo-denyEmbarkStudios/cargo-deny-action
❌ GitHub Action for cargo-deny 🦀
- CActive★ 6541 months ago64Snyksnyk/actions
A set of GitHub actions for checking your projects for vulnerabilities.
- CActive★ 12415 days ago64Cimon by CycodeCycodeLabs/cimon-action
Runtime Security Solution for your CI/CD Pipeline
- CActive★ 828 days ago641Password CLI1Password/install-cli-action
Install 1Password CLI into your GitHub Actions jobs.
- CActive★ 1.4k1 months ago64Authenticate to Google Cloudgoogle-github-actions/auth
A GitHub Action for authenticating to Google Cloud.
- CActive★ 35115 days ago63GitGuardian Shield ActionGitGuardian/ggshield-action
GitGuardian Shield GitHub Action - Find exposed credentials in your commits
- CActive★ 617 days ago63Runseal - Supply Chain Security Actionnolabs-ai/runseal
Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.
- CActive★ 3832 months ago63Import GPGcrazy-max/ghaction-import-gpg
GitHub Action to import a GPG key
- CActive★ 1389 days ago62Envilder GitHub Actionmacalbert/envilder
One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift.