ActionRank

Security GitHub Actions

Scan code, dependencies, secrets and workflows for vulnerabilities.

101 actions

  1. C
    VirusTotal GitHub Action

    GitHub Action to upload and scan files with VirusTotal

    62
  2. C
    Get Secret Manager secrets

    A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.

    62
  3. C
    Wait for secrets

    Publish from GitHub Actions using multi-factor authentication

    61
  4. C
    Create GitHub App Token

    GitHub Action for creating a GitHub App Installation Access Token

    61
  5. C
    ZAP Full Scan

    A GitHub Action for running the ZAP Full scan

    60
  6. C
    vibecop PR Gate

    AI code quality toolkit — deterministic linter for the AI coding era. 22 detectors, GitHub Action PR gate, zero LLM required.

    60
  7. C
    ZAP Baseline Scan

    A GitHub Action for running the ZAP Baseline scan

    60
  8. C
    AI-BOM Scan

    AI Bill of Materials — discover every AI agent, model, and API in your infrastructure

    60
  9. C
    VulnHawk Security Scan

    AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

    59
  10. C
    ZAP API Scan

    A GitHub Action for running the ZAP API scan

    58
  11. C
    Sonarless Code Scan

    SonarQube Scan CLI + GitHub Action without a need of a dedicated hosted SonarQube Server

    57
  12. C
    Differential ShellCheck

    🐚 GitHub Action for running ShellCheck differentially

    56
  13. C
    Sync GitHub Security Alerts with Jira

    Github Action for integrating Security Alerts with JIRA

    56
  14. C
    SLSA Build Provenance Action

    Github Action implementation of SLSA Provenance Generation

    56
  15. D
    setup-git-credentials

    GitHub action to enable cloning private respositories.

    53
  16. D
    skill-publish

    GitHub Action and CLI to validate, monitor, and publish verifiable skills (SKILL.md) via Registry Broker

    53
  17. D
    Git Anti Virus Scan

    Git Anti-Virus Scan Action - Detect trojans, viruses, malware & other malicious threats.

    52
  18. D
    Loxcan

    🔍 Universal Lock File Scanner for Git. (Lock + Scan = LoXcan!)

    49
  19. D
    gh-action-pip-audit

    A GitHub Action for pip-audit

    49
  20. D
    Get GKE Credentials

    A GitHub Action that configure authentication to a GKE cluster.

    49
  21. D
    Good Egg: Trust Scoring PRs

    Trust scoring for GitHub PR authors based on contribution history.

    48
  22. D
    NAME

    GitHub Actions CI/CD - Master Template & Reusable Workflows Library - Docker Builds, AWS, Python, Terraform, Jenkins, Linting, Security Scanning, Make Builds etc.

    48
  23. D
    OpenSSF Scorecard Monitor

    Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts

    44
  24. D
    Link Snitch

    GitHub Action to scan your site for broken links so you can fix them 🔗

    43
  25. D
    Django Security Check

    Helps you continuously monitor and fix common security vulnerabilities in your Django application.

    43
  26. D
    Dependencies license compliance checker

    GitHub Action for license compliance: Python, JavaScript, iOS, Android and more.

    41
  27. F
    Bridgecrew Github Action

    This GitHub Action runs Bridgecrew against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.

    39
  28. F
    Secrets Sync Action

    A Github Action that can sync secrets from one repository to many others.

    35
  29. F
    Create .env file

    Github Action to create a .env file with Github Secrets

    35
  30. F
    Semgrep Action

    This project is deprecated. Use https://github.com/returntocorp/semgrep instead

    35
  31. F
    Secrets Sync Action

    A Github Action that can sync secrets from one repository to many others.

    35
  32. F
    Terraform security scan

    Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec

    35
  33. F
    Trivy Action

    GitHub Issue + Trivy Action

    34
  34. F
    SonarQube Scan

    Integrate SonarQube scanner to GitHub Actions

    34
  35. F
    Nightfall DLP Action

    GitHub Data Loss Prevention (DLP) Action: Scan Pull Requests for sensitive data, like credentials & secrets, PII, credit card numbers, and more.

    34
  36. F
    AWS Secrets Manager Action

    Use secrets from AWS Secrets Manager as environment variables in your GitHub Actions workflow

    33
  37. F
    GitHub Action to unlock git-crypt secrets

    Github Action to unlock git-crypt secrets

    33
  38. F
    SonarQube Cloud Scan

    Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.

    32
  39. F
    aws-secrets-manager-actions

    🔒 GitHub Action for AWS Secrets Manager

    32
  40. F
    Aqua Tracee

    Protect GitHub Actions with Tracee

    32
  41. F
    SAML.to Assume AWS Role

    Assume AWS IAM Roles using SAML.to in GitHub Actions

    31
  42. F
    AWS Security Group Add IP

    GitHub Action for AWS Security Group Add IP

    29
  43. F
    Transmute

    Transmute

    28
  44. F
    iam-lint

    Github action for linting AWS IAM policy documents

    28
  45. F
    dlint check

    Github Action to run dlint security linter on your Python code

    27
  46. F
    Docker Vulnerability Scan With Phonito Security

    Free Docker Vulnerability Scanning for CI/CD integration

    26
  47. F
    Reposaur

    Open source compliance tool for development platforms.

    25
  48. F
    Gradle Wrapper Validation

    Gradle Wrapper Validation Action

    24
  49. F
    GitHub App token

    Impersonate a GitHub App in a GitHub Action

    24
  50. F
    SecretHub

    Load secrets into GitHub Actions

    22