ActionRank

Security GitHub Actions

Scan code, dependencies, secrets and workflows for vulnerabilities.

9 actions · stale

B
Shai-Hulud 2.0 Detectorgensecaihq/Shai-Hulud-2.0-Detector

Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.

Stale144Updated 5 months ago70/100
C
vibecop PR Gatebhvbhushan/vibecop

AI code quality toolkit — deterministic linter for the AI coding era. 22 detectors, GitHub Action PR gate, zero LLM required.

Stale55Updated 3 months ago62/100
C
AI-BOM ScanTrusera/ai-bom

AI Bill of Materials — discover every AI agent, model, and API in your infrastructure

Stale296Updated 3 months ago61/100
C
Differential ShellCheckredhat-plumbers-in-action/differential-shellcheck

🐚 GitHub Action for running ShellCheck differentially

Stale65Updated 3 months ago57/100
C
Bullfrog Secure Runnerbullfrogsec/bullfrog

Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows

Stale127Updated 4 months ago57/100
D
Get Secret Manager secretsgoogle-github-actions/get-secretmanager-secrets

A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.

Stale197Updated 11 months ago52/100
D
Wait for secretsstep-security/wait-for-secrets

Publish from GitHub Actions using multi-factor authentication

Stale299Updated 5 months ago51/100
D
Loxcansiketyan/loxcan

🔍 Universal Lock File Scanner for Git. (Lock + Scan = LoXcan!)

Stale66Updated 6 months ago50/100
D
Good Egg: Trust Scoring PRs2ndSetAI/good-egg

Trust scoring for GitHub PR authors based on contribution history.

Stale51Updated 4 months ago49/100