ActionRank

Security GitHub Actions

Scan code, dependencies, secrets and workflows for vulnerabilities.

43 actions · active

B
Fenceopenai/fence

A fence keeps things out, but also in. This project is still in early, and active development.

Active129Updated 2 days ago82/100
B
Pipelock Agent Security ScanluckyPipewrench/pipelock

Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.

Active786Updated today79/100
B
Lightning Flow ScanFlow-Scanner/lightning-flow-scanner

A standalone Salesforce Flow analysis engine available as a CLI plugin, VS Code extension, and GitHub Action. Scans metadata for 20+ issues, including hardcoded IDs, unsafe contexts, inefficient DML operations, recursion risks, and more. Supports auto-fixes, rule configs, CI/CD integration, and UMD builds for flexible use.

Active173Updated 13 days ago78/100
B
Harden-Runnerstep-security/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Active1.2kUpdated 26 days ago78/100
B
Anchore Container Scananchore/scan-action

Anchore container analysis and scan provided as a GitHub Action

Active286Updated 2 days ago76/100
B
Skylos - Python SAST, Dead Code Detection & PR Gateduriantaco/skylos

Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/

Active482Updated 2 days ago76/100
B
OSSF Scorecard actionossf/scorecard-action

Official GitHub Action for OpenSSF Scorecard.

Active402Updated 3 days ago75/100
B
Test LLM outputspromptfoo/promptfoo-action

The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.

Active69Updated 17 days ago74/100
B
Provenance downgrade checkdanielroe/provenance-action

Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status

Active306Updated 5 days ago74/100
B
Agents ShipgateThreeMoonsLab/agents-shipgate

The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.

Active106Updated yesterday73/100
B
Aguara Security Scannergaragon/aguara

The open source security engine for AI agent and supply-chain trust.

Active85Updated 8 days ago73/100
B
gh-action-sigstore-pythonsigstore/gh-action-sigstore-python

A GitHub Action for sigstore-python

Active70Updated yesterday73/100
B
AI Surface Checkapisec-inc/AI-Surface

Find and govern AI attack surfaces in application code at PR time. Free, OSS, runs offline.

Active80Updated 15 days ago72/100
B
Gitleaksgitleaks/gitleaks-action

Protect your secrets using Gitleaks-Action

Active625Updated 12 days ago72/100
B
pypi-publishpypa/gh-action-pypi-publish

The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish

Active1.2kUpdated 4 days ago71/100
B
pinactsuzuki-shunsuke/pinact-action

GitHub Actions to pin GitHub Actions by pinact

Active75Updated today70/100
C
Aqua Security Trivyaquasecurity/trivy-action

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Active1.4kUpdated 1 months ago69/100
C
Container Scancrazy-max/ghaction-container-scan

GitHub Action to check for vulnerabilities in your container image

Active74Updated 1 months ago69/100
C
Docker Scoutdocker/scout-action

Docker Scout GitHub Action

Active140Updated 2 days ago68/100
C
HashiCorp Vaulthashicorp/vault-action

A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.

Active511Updated 5 days ago67/100
C
Authenticate to Google Cloudgoogle-github-actions/auth

A GitHub Action for authenticating to Google Cloud.

Active1.4kUpdated 3 days ago66/100
C
Load secrets from 1Password1Password/load-secrets-action

Load secrets from 1Password into your GitHub Actions jobs

Active331Updated yesterday66/100
C
VulnHawk Security Scanmomenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Active77Updated 1 months ago66/100
C
VirusTotal GitHub Actioncrazy-max/ghaction-virustotal

GitHub Action to upload and scan files with VirusTotal

Active229Updated 1 months ago65/100
C
Frogbot by JFrogjfrog/frogbot

🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖

Active370Updated 6 days ago65/100
C
osv-scannergoogle/osv-scanner-action
Active91Updated 9 days ago65/100
C
CodeQL: Stubgithub/codeql-action

Actions for running CodeQL analysis

Active1.6kUpdated yesterday65/100
C
Runseal - Supply Chain Security Actionnolabs-ai/runseal

Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.

Active56Updated 28 days ago64/100
C
Run tfsec with reviewdogreviewdog/action-tfsec

Run tfsec with reviewdog on pull requests to enforce security best practices

Active76Updated 3 days ago64/100
C
GitGuardian Shield ActionGitGuardian/ggshield-action

GitGuardian Shield GitHub Action - Find exposed credentials in your commits

Active349Updated 4 days ago63/100
C
1Password CLI1Password/install-cli-action

Install 1Password CLI into your GitHub Actions jobs.

Active79Updated 9 days ago63/100
C
Snyksnyk/actions

A set of GitHub actions for checking your projects for vulnerabilities.

Active650Updated 2 months ago63/100
C
Cimon by CycodeCycodeLabs/cimon-action

Runtime Security Solution for your CI/CD Pipeline

Active122Updated 2 months ago62/100
C
Sonarless Code Scangitricko/sonarless

SonarQube Scan CLI + GitHub Action without a need of a dedicated hosted SonarQube Server

Active50Updated 2 months ago62/100
C
Sync GitHub Security Alerts with Jirareload/github-security-jira

Github Action for integrating Security Alerts with JIRA

Active52Updated 3 days ago57/100
C
ZAP Baseline Scanzaproxy/action-baseline

A GitHub Action for running the ZAP Baseline scan

Active365Updated 2 months ago56/100
C
SLSA Build Provenance Actionphilips-labs/slsa-provenance-action

Github Action implementation of SLSA Provenance Generation

Active50Updated 22 days ago56/100
C
ZAP Full Scanzaproxy/action-full-scan

A GitHub Action for running the ZAP Full scan

Active380Updated 2 months ago56/100
C
ZAP API Scanzaproxy/action-api-scan

A GitHub Action for running the ZAP API scan

Active75Updated 2 months ago55/100
C
gh-action-pip-auditpypa/gh-action-pip-audit

A GitHub Action for pip-audit

Active88Updated 1 months ago55/100
C
Git Anti Virus Scandjdefi/gitavscan

Git Anti-Virus Scan Action - Detect trojans, viruses, malware & other malicious threats.

Active54Updated 1 months ago55/100
D
Django Security Checkvictoriadrake/django-security-check

Helps you continuously monitor and fix common security vulnerabilities in your Django application.

Active93Updated 1 months ago46/100
D
Link Snitchvictoriadrake/link-snitch

GitHub Action to scan your site for broken links so you can fix them 🔗

Active66Updated 1 months ago46/100