Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
43 actions · active
A fence keeps things out, but also in. This project is still in early, and active development.
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
A standalone Salesforce Flow analysis engine available as a CLI plugin, VS Code extension, and GitHub Action. Scans metadata for 20+ issues, including hardcoded IDs, unsafe contexts, inefficient DML operations, recursion risks, and more. Supports auto-fixes, rule configs, CI/CD integration, and UMD builds for flexible use.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Anchore container analysis and scan provided as a GitHub Action
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
Official GitHub Action for OpenSSF Scorecard.
The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.
The open source security engine for AI agent and supply-chain trust.
A GitHub Action for sigstore-python
Find and govern AI attack surfaces in application code at PR time. Free, OSS, runs offline.
Protect your secrets using Gitleaks-Action
The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish
GitHub Actions to pin GitHub Actions by pinact
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
GitHub Action to check for vulnerabilities in your container image
Docker Scout GitHub Action
A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.
A GitHub Action for authenticating to Google Cloud.
Load secrets from 1Password into your GitHub Actions jobs
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
GitHub Action to upload and scan files with VirusTotal
🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖
Actions for running CodeQL analysis
Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.
Run tfsec with reviewdog on pull requests to enforce security best practices
GitGuardian Shield GitHub Action - Find exposed credentials in your commits
Install 1Password CLI into your GitHub Actions jobs.
A set of GitHub actions for checking your projects for vulnerabilities.
Runtime Security Solution for your CI/CD Pipeline
SonarQube Scan CLI + GitHub Action without a need of a dedicated hosted SonarQube Server
Github Action for integrating Security Alerts with JIRA
A GitHub Action for running the ZAP Baseline scan
Github Action implementation of SLSA Provenance Generation
A GitHub Action for running the ZAP Full scan
A GitHub Action for running the ZAP API scan
A GitHub Action for pip-audit
Git Anti-Virus Scan Action - Detect trojans, viruses, malware & other malicious threats.
Helps you continuously monitor and fix common security vulnerabilities in your Django application.
GitHub Action to scan your site for broken links so you can fix them 🔗