







Enhance your workflow with extensions
Tools from the community and partners to simplify tasks and automate processes
Security actions
TruffleHog OSS
ActionFind and verify leaked credentials in your source code
Prowler Security Scan
ActionRun Prowler cloud security scanner using the official Docker image
MegaLinter
ActionCombine all available linters to automatically validate your sources without configuration
Is Website vulnerable
ActionScans a url for public javascript library vulnerabilities
Aqua Security Trivy
ActionScans container images for vulnerabilities with Trivy
OWASP Noir Action
ActionHunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface
Authenticate to Google Cloud from GitHub Actions via Workload Identity Federation or service account keys
Stelligent cfn_nag
ActionExecute cfn_nag_scan against the code in the repository where the GitHub Action workflow is run
Harden-Runner
ActionHarden-Runner provides runtime security for GitHub-hosted and self-hosted runners
Attest Build Provenance
ActionGenerate provenance attestations for build artifacts
Scan Claude Code configurations for security issues
Dependency Review
ActionPrevent the introduction of dependencies with known vulnerabilities
Legitify Analyze
ActionLegitify GitHub Action
Create GitHub App Token
ActionGitHub Action for creating a GitHub App installation access token
mobsfscan
Actionmobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code
Scan your project for AI agent security risks. Detects secrets, misconfigurations, and generates a tailored security config
Plumber Score
ActionPlumber detects CI/CD security issues in your GitHub workflows and gives you a score
Pompelmi ClamAV Scanner
ActionScan for viruses with ClamAV (bundled) — no daemon, no cloud, zero external dependencies
Snyk
ActionCheck your applications for vulnerabilties using Snyk
CVE Lite CLI
ActionRun CVE Lite CLI in GitHub Actions for JS/TS dependency vulnerability scanning