ActionRank

Security GitHub Actions

Scan code, dependencies, secrets and workflows for vulnerabilities.

50 actions

B
Fenceopenai/fence

A fence keeps things out, but also in. This project is still in early, and active development.

Active129Updated 2 days ago82/100
B
Harden-Runnerstep-security/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Active1.2kUpdated 25 days ago78/100
B
Skylos - Python SAST, Dead Code Detection & PR Gateduriantaco/skylos

Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/

Active482Updated 2 days ago76/100
B
Anchore Container Scananchore/scan-action

Anchore container analysis and scan provided as a GitHub Action

Active286Updated 2 days ago76/100
B
OSSF Scorecard actionossf/scorecard-action

Official GitHub Action for OpenSSF Scorecard.

Active403Updated 3 days ago75/100
B
Provenance downgrade checkdanielroe/provenance-action

Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status

Active306Updated 5 days ago74/100
B
Aguara Security Scannergaragon/aguara

The open source security engine for AI agent and supply-chain trust.

Active85Updated 8 days ago73/100
B
Agents ShipgateThreeMoonsLab/agents-shipgate

The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.

Active106Updated yesterday73/100
B
gh-action-sigstore-pythonsigstore/gh-action-sigstore-python

A GitHub Action for sigstore-python

Active70Updated yesterday73/100
B
Gitleaksgitleaks/gitleaks-action

Protect your secrets using Gitleaks-Action

Active625Updated 12 days ago72/100
B
pypi-publishpypa/gh-action-pypi-publish

The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish

Active1.2kUpdated 4 days ago71/100
B
Shai-Hulud 2.0 Detectorgensecaihq/Shai-Hulud-2.0-Detector

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

Stale144Updated 5 months ago70/100
B
pinactsuzuki-shunsuke/pinact-action

GitHub Actions to pin GitHub Actions by pinact

Active75Updated today70/100
C
Container Scancrazy-max/ghaction-container-scan

GitHub Action to check for vulnerabilities in your container image

Active74Updated 1 months ago69/100
C
Aqua Security Trivyaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Active1.4kUpdated 1 months ago69/100
C
Docker Scoutdocker/scout-action

Docker Scout GitHub Action

Active140Updated 2 days ago68/100
C
HashiCorp Vaulthashicorp/vault-action

A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.

Active511Updated 5 days ago67/100
C
Load secrets from 1Password1Password/load-secrets-action

Load secrets from 1Password into your GitHub Actions jobs

Active331Updated yesterday66/100
C
VulnHawk Security Scanmomenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Active77Updated 1 months ago66/100
C
Authenticate to Google Cloudgoogle-github-actions/auth

A GitHub Action for authenticating to Google Cloud.

Active1.4kUpdated 3 days ago66/100
C
CodeQL: Stubgithub/codeql-action

Actions for running CodeQL analysis

Active1.6kUpdated yesterday65/100
C
Frogbot by JFrogjfrog/frogbot

🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖

Active370Updated 5 days ago65/100
C
VirusTotal GitHub Actioncrazy-max/ghaction-virustotal

GitHub Action to upload and scan files with VirusTotal

Active229Updated 1 months ago65/100
C
osv-scannergoogle/osv-scanner-action
Active91Updated 9 days ago65/100
C
1Password CLI1Password/install-cli-action

Install 1Password CLI into your GitHub Actions jobs.

Active79Updated 9 days ago63/100
C
GitGuardian Shield ActionGitGuardian/ggshield-action

GitGuardian Shield GitHub Action - Find exposed credentials in your commits

Active349Updated 4 days ago63/100
C
Sonarless Code Scangitricko/sonarless

SonarQube Scan CLI + GitHub Action without a need of a dedicated hosted SonarQube Server

Active50Updated 2 months ago62/100
C
Cimon by CycodeCycodeLabs/cimon-action

Runtime Security Solution for your CI/CD Pipeline

Active122Updated 2 months ago62/100
C
AI-BOM ScanTrusera/ai-bom

AI Bill of Materials — discover every AI agent, model, and API in your infrastructure

Stale296Updated 3 months ago61/100
C
Bullfrog Secure Runnerbullfrogsec/bullfrog

Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows

Stale127Updated 4 months ago57/100
C
SLSA Build Provenance Actionphilips-labs/slsa-provenance-action

Github Action implementation of SLSA Provenance Generation

Active50Updated 22 days ago56/100
C
ZAP Full Scanzaproxy/action-full-scan

A GitHub Action for running the ZAP Full scan

Active380Updated 2 months ago56/100
C
ZAP Baseline Scanzaproxy/action-baseline

A GitHub Action for running the ZAP Baseline scan

Active365Updated 2 months ago56/100
C
gh-action-pip-auditpypa/gh-action-pip-audit

A GitHub Action for pip-audit

Active88Updated 1 months ago55/100
C
ZAP API Scanzaproxy/action-api-scan

A GitHub Action for running the ZAP API scan

Active75Updated 2 months ago55/100
D
Get Secret Manager secretsgoogle-github-actions/get-secretmanager-secrets

A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.

Stale197Updated 11 months ago52/100
D
Wait for secretsstep-security/wait-for-secrets

Publish from GitHub Actions using multi-factor authentication

Stale299Updated 5 months ago51/100
D
Link Snitchvictoriadrake/link-snitch

:octocat: GitHub Action to scan your site for broken links so you can fix them 🔗

Active66Updated 1 months ago46/100
D
Django Security Checkvictoriadrake/django-security-check

Helps you continuously monitor and fix common security vulnerabilities in your Django application.

Active93Updated 1 months ago46/100
D
Bridgecrew Github Actionbridgecrewio/bridgecrew-action

This GitHub Action runs Bridgecrew against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.

Abandoned73Updated 1 year ago40/100
F
Secrets Sync Actionjpoehnelt/secrets-sync-action

A Github Action that can sync secrets from one repository to many others.

Abandoned336Updated 1 year ago36/100
F
Semgrep Actionsemgrep/semgrep-action

This project is deprecated. Use https://github.com/returntocorp/semgrep instead

Abandoned76Updated 2 years ago35/100
F
Create .env fileSpicyPizza/create-envfile

Github Action to create a .env file with Github Secrets

Abandoned476Updated 2 years ago35/100
F
SonarQube Scankitabisa/sonarqube-action

Integrate SonarQube scanner to GitHub Actions

Abandoned159Updated 1 year ago34/100
F
Trivy Actionlazy-actions/gitrivy

GitHub Issue + Trivy Action

Abandoned55Updated 5 years ago34/100
F
GitHub Action to unlock git-crypt secretssliteteam/github-action-git-crypt-unlock

Github Action to unlock git-crypt secrets

Abandoned55Updated 2 years ago33/100
F
SonarQube Cloud ScanSonarSource/sonarcloud-github-action

Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.

Abandoned608Updated 11 months ago32/100
F
Aqua Traceeaquasecurity/tracee-action

Protect GitHub Actions with Tracee

Abandoned81Updated 1 year ago32/100
F
Reposaurreposaur/reposaur

Open source compliance tool for development platforms.

Abandoned286Updated 3 years ago25/100
F
Expo Preview Actionexpo/expo-preview-action

With this preview action, you can test changes made in pull requests via Expo Go or custom development client (created with expo-dev-client) just by scanning QR code.

Abandoned82Updated 2 years ago22/100