Security & Supply Chain
Scan for vulnerabilities and harden the CI supply chain.
actions/dependency-review-actionBlock pull requests that introduce dependencies with known vulnerabilities or bad licenses.
aquasecurity/trivy-actionScan container images, filesystems, and IaC for vulnerabilities with Trivy.
github/codeql-actionRun GitHub CodeQL static analysis to find security vulnerabilities in your code.
gitleaks/gitleaks-actionScan commits and pull requests for hardcoded secrets with Gitleaks.
ossf/scorecard-actionRun OpenSSF Scorecard supply-chain checks on your repo and surface results in code scanning.
step-security/harden-runnerMonitor and restrict a runner's network egress to detect and block CI supply-chain attacks.