Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
57 actions · active
- BActive★ 919today84Pipelock Agent Security ScanluckyPipewrench/pipelock
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
- BActive★ 1549 days ago83Fenceopenai/fence
A fence keeps things out, but also in. This project is still in early, and active development.
- BActive★ 895 days ago80Agents ShipgateThreeMoonsLab/agents-shipgate
The deterministic merge gate for AI-generated agent capability changes — a local-first, static Tool-Use Readiness review for MCP, OpenAPI, and SDK tool surfaces. Open-source CLI + GitHub Action.
- BActive★ 1511 months ago80Shai-Hulud 2.0 Detectorgensecaihq/Shai-Hulud-2.0-Detector
GitHub Action that detects the Shai-Hulud 2.0 (Nov 2025) and ChainDrop (Aug 2026) npm supply-chain attacks. Scans dependencies, lockfiles and CI workflows against a daily-updated database of 1,200+ compromised packages, flags malicious install scripts, TruffleHog secret theft and SHA1HULUD runners. SARIF output for GitHub Code Scanning.
- BActive★ 1.3k1 months ago79Harden-Runnerstep-security/harden-runner
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.
- BActive★ 288yesterday79Anchore Container Scananchore/scan-action
Anchore container analysis and scan provided as a GitHub Action
- BActive★ 3ktoday78"Configure AWS Credentials" Action for GitHub Actionsaws-actions/configure-aws-credentials
Configure AWS credential environment variables for use in other GitHub Actions.
- BActive★ 1761 months ago78Lightning Flow ScanFlow-Scanner/lightning-flow-scanner
Lightning Flow Scanner is an open-source Salesforce CLI plugin, VS Code extension, and GitHub Action for analysing and optimising Salesforce Flows. It scans metadata against 20+ community-driven rules — hardcoded IDs, missing fault paths, inefficient DML, recursion risks, and more. Includes auto-fixes, configurable rules, and CI/CD integration
- BActive★ 841today77Skylos - Python SAST, Dead Code Detection & PR Gateduriantaco/skylos
Open source local-first PR scanner that finds dead code, security bugs, secrets, quality regressions, and AI-code mistakes before merge. For first timers refer to https://duriantaco.github.io/skylos/repo-map/
- BActive★ 2165 days ago76node9 Agent Securitynode9-ai/node9-proxy
IAM for your AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run, and keep every action on the record.
- BActive★ 16624 days ago75zizmor-actionzizmorcore/zizmor-action
Run zizmor from GitHub Actions!
- BActive★ 1381 months ago74Codex Guard PR Quality GateAkimiya-z/codex-guard
Quality gate for AI/Codex-generated pull requests: blocks TODO leftovers, leaked secrets, sloppy commits and red CI before they reach main.
- BActive★ 7521 days ago74Test LLM outputspromptfoo/promptfoo-action
The GitHub Action for Promptfoo. Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.
- BActive★ 4201 months ago74OSSF Scorecard actionossf/scorecard-action
Official GitHub Action for OpenSSF Scorecard.
- BActive★ 715 days ago73gh-action-sigstore-pythonsigstore/gh-action-sigstore-python
A GitHub Action for sigstore-python
- BActive★ 9322 days ago73Aguara Security Scannergaragon/aguara
The open source security engine for AI agent and supply-chain trust.
- BActive★ 5513 days ago73Ensure SHA Pinned Actionszgosalvez/github-actions-ensure-sha-pinned-actions
A Github Action to ensure that actions are pinned to full length commit SHAs
- BActive★ 2219 days ago73actions--access-tokenqoomon/actions--access-token
Get rid of personal access tokens (PAT) and credential management, use temporary GitHub Application access tokens instead!
- BActive★ 19423 days ago72AWS Secrets Manager GitHub Actionaws-actions/aws-secretsmanager-get-secrets
- BActive★ 1775 days ago72AletheoreAletheore/Aletheore
Evidence-grounded repository audit CLI - deterministic scanner, MCP server, live dashboard, and a GitHub Action that posts PR diffs.
- BActive★ 5812 days ago72compose-linttmatens/compose-lint
Security-focused linter for Docker Compose files. Catches dangerous misconfigurations before they reach production. Grounded in OWASP and CIS Docker Benchmark.
- BActive★ 13411 days ago72AI Surface Checkapisec-inc/AI-Surface
Find and govern AI attack surfaces in application code, at PR time and inside your AI coding tool (MCP server, Claude Code hook). Free, OSS, runs offline.
- BActive★ 3085 days ago71Provenance downgrade checkdanielroe/provenance-action
Fail CI when dependencies in your lockfile lose npm provenance or trusted publisher status
- BActive★ 775 days ago70pinactsuzuki-shunsuke/pinact-action
GitHub Actions to pin GitHub Actions by pinact
- CActive★ 6618 days ago69Differential ShellCheckredhat-plumbers-in-action/differential-shellcheck
🐚 GitHub Action for running ShellCheck differentially
- CActive★ 971 months ago69Repo Publication Auditduy90utc528/repo-publication-audit
Dependency-free preflight checks for repositories before making them public
- CActive★ 1.2ktoday69pypi-publishpypa/gh-action-pypi-publish
The blessed GitHub Action, for publishing your distribution files to PyPI, the tokenless way: https://github.com/marketplace/actions/pypi-publish
- CActive★ 1.4kyesterday68Aqua Security Trivyaquasecurity/trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
- CActive★ 6572 months ago68Gitleaksgitleaks/gitleaks-action
Protect your secrets using Gitleaks-Action
- CActive★ 311today68Qodana ScanJetBrains/qodana-action
⚙️ Scan your Go, Java, Kotlin, PHP, Python, JavaScript, TypeScript, .NET projects at GitHub with Qodana. This repository contains Qodana for Azure, GitHub, CircleCI and Gradle
- CActive★ 1291 months ago67Bullfrog Secure Runnerbullfrogsec/bullfrog
Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows
- CActive★ 7613 days ago67Run tfsec with reviewdogreviewdog/action-tfsec
Run tfsec with reviewdog on pull requests to enforce security best practices
- CActive★ 981 months ago67RepoCare repository healthlstsavr/repocare
A local-first repository health scanner with actionable scoring for open-source maintainers.
- CActive★ 9719 days ago66osv-scannergoogle/osv-scanner-action
- CActive★ 28618 days ago66Import Code-Signing CertificatesApple-Actions/import-codesign-certs
GitHub Action for Importing Code-signing Certificates into a Keychain
- CActive★ 34716 days ago66Load secrets from 1Password1Password/load-secrets-action
Load secrets from 1Password into your GitHub Actions jobs
- CActive★ 9718 days ago66Download Apple Provisioning ProfilesApple-Actions/download-provisioning-profiles
Github Action for downloading provisioning profiles from Apple AppStore Connect
- CActive★ 6543 days ago66Snyksnyk/actions
A set of GitHub actions for checking your projects for vulnerabilities.
- CActive★ 5121 months ago65HashiCorp Vaulthashicorp/vault-action
A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.
- CActive★ 1.7ktoday65CodeQL: Stubgithub/codeql-action
Actions for running CodeQL analysis
- CActive★ 8224 days ago641Password CLI1Password/install-cli-action
Install 1Password CLI into your GitHub Actions jobs.
- CActive★ 1942 months ago64cargo-denyEmbarkStudios/cargo-deny-action
❌ GitHub Action for cargo-deny 🦀
- CActive★ 1251 months ago64Cimon by CycodeCycodeLabs/cimon-action
Runtime Security Solution for your CI/CD Pipeline
- CActive★ 37315 days ago64Frogbot by JFrogjfrog/frogbot
🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖
- CActive★ 1422 months ago64Docker Scoutdocker/scout-action
Docker Scout GitHub Action
- CActive★ 1.4k2 months ago63Authenticate to Google Cloudgoogle-github-actions/auth
A GitHub Action for authenticating to Google Cloud.
- CActive★ 6211 days ago63Runseal - Supply Chain Security Actionnolabs-ai/runseal
Sealed execution environment for GitHub Actions. Stop supply chain attacks dead in their tracks.
- CActive★ 3508 days ago63GitGuardian Shield ActionGitGuardian/ggshield-action
GitGuardian Shield GitHub Action - Find exposed credentials in your commits
- CActive★ 1981 months ago62Get Secret Manager secretsgoogle-github-actions/get-secretmanager-secrets
A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.
- CActive★ 1385 days ago61Envilder GitHub Actionmacalbert/envilder
One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift.