Security GitHub Actions
Scan code, dependencies, secrets and workflows for vulnerabilities.
5 actions · stale
BCCDD
Shai-Hulud 2.0 Detectorgensecaihq/Shai-Hulud-2.0-Detector
Detect npm packages compromised in the Shai-Hulud 2.0 supply chain attack (Nov 2025). Scans for 790+ malicious packages, suspicious scripts, TruffleHog activity, SHA1HULUD runners, and secrets exfiltration. GitHub Action with SARIF support.
Stale★ 144Updated 5 months ago70/100
AI-BOM ScanTrusera/ai-bom
AI Bill of Materials — discover every AI agent, model, and API in your infrastructure
Stale★ 296Updated 3 months ago61/100
Bullfrog Secure Runnerbullfrogsec/bullfrog
Simple plug-and-play Github Action to block unauthorized outbound traffic (egress) in your Github workflows
Stale★ 127Updated 4 months ago57/100
Get Secret Manager secretsgoogle-github-actions/get-secretmanager-secrets
A GitHub Action for accessing secrets from Google Secret Manager and making them available as outputs.
Stale★ 197Updated 11 months ago52/100
Wait for secretsstep-security/wait-for-secrets
Publish from GitHub Actions using multi-factor authentication
Stale★ 299Updated 5 months ago51/100