Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
9 actions · stale
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
AI code quality toolkit — deterministic linter for the AI coding era. 22 detectors, GitHub Action PR gate, zero LLM required.
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
🐚 GitHub Action for running ShellCheck differentially
Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows
A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.
Publish from GitHub Actions using multi-factor authentication
🔍 Universal Lock File Scanner for Git. (Lock + Scan = LoXcan!)
Trust scoring for GitHub PR authors based on contribution history.