Skip to content

Enhance your workflow with extensions

Tools from the community and partners to simplify tasks and automate processes

    Security actions

    Find, fix, and prevent security vulnerabilities before they can be exploited.

    Find and verify leaked credentials in your source code

    Run Prowler cloud security scanner using the official Docker image

    Combine all available linters to automatically validate your sources without configuration

    Scans a url for public javascript library vulnerabilities

    Scans container images for vulnerabilities with Trivy

    Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface

    Authenticate to Google Cloud from GitHub Actions via Workload Identity Federation or service account keys

    Execute cfn_nag_scan against the code in the repository where the GitHub Action workflow is run

    Harden-Runner provides runtime security for GitHub-hosted and self-hosted runners

    Generate provenance attestations for build artifacts

    Scan Claude Code configurations for security issues

    Prevent the introduction of dependencies with known vulnerabilities

    Legitify GitHub Action

    GitHub Action for creating a GitHub App installation access token

    mobsfscan

    Action

    mobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code

    Scan your project for AI agent security risks. Detects secrets, misconfigurations, and generates a tailored security config

    Plumber detects CI/CD security issues in your GitHub workflows and gives you a score

    Scan for viruses with ClamAV (bundled) — no daemon, no cloud, zero external dependencies

    Snyk

    Action

    Check your applications for vulnerabilties using Snyk

    Run CVE Lite CLI in GitHub Actions for JS/TS dependency vulnerability scanning