Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
50 actions
A fence keeps things out, but also in. This project is still in early, and active development.
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
Anchore container analysis and scan provided as a GitHub Action
Official GitHub Action for OpenSSF Scorecard.
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
The open source security engine for AI agent and supply-chain trust.
The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.
A GitHub Action for sigstore-python
Protect your secrets using Gitleaks-Action
The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
GitHub Actions to pin GitHub Actions by pinact
GitHub Action to check for vulnerabilities in your container image
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
Docker Scout GitHub Action
A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.
Load secrets from 1Password into your GitHub Actions jobs
AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
A GitHub Action for authenticating to Google Cloud.
Actions for running CodeQL analysis
🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖
GitHub Action to upload and scan files with VirusTotal
Install 1Password CLI into your GitHub Actions jobs.
GitGuardian Shield GitHub Action - Find exposed credentials in your commits
SonarQube Scan CLI + GitHub Action without a need of a dedicated hosted SonarQube Server
Runtime Security Solution for your CI/CD Pipeline
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows
Github Action implementation of SLSA Provenance Generation
A GitHub Action for running the ZAP Full scan
A GitHub Action for running the ZAP Baseline scan
A GitHub Action for pip-audit
A GitHub Action for running the ZAP API scan
A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.
Publish from GitHub Actions using multi-factor authentication
:octocat: GitHub Action to scan your site for broken links so you can fix them 🔗
Helps you continuously monitor and fix common security vulnerabilities in your Django application.
This GitHub Action runs Bridgecrew against infrastructure-as-code, open source packages, container images, and CI/CD configurations to identify misconfigurations, vulnerabilities, and license compliance issues.
A Github Action that can sync secrets from one repository to many others.
This project is deprecated. Use https://github.com/returntocorp/semgrep instead
Github Action to create a .env file with Github Secrets
Integrate SonarQube scanner to GitHub Actions
GitHub Issue + Trivy Action
Github Action to unlock git-crypt secrets
Deprecated. Use https://github.com/SonarSource/sonarqube-scan-action instead.
Protect GitHub Actions with Tracee
Open source compliance tool for development platforms.
With this preview action, you can test changes made in pull requests via Expo Go or custom development client (created with expo-dev-client) just by scanning QR code.