Skip to main content

Browse the directory

Showing 8 resources for "github-actions"
Saved
Active

2 trusted · 6 review in this set — compare to see which signals differ.

Trust snapshot

8 results in this view

Claimed
0%(0/8)

3 trust signals differ in this sample: Package trust, Source provenance, Submitter

Signals differ on Package trust, Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

8 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (8/8)

Adoption queue

Browse adoption queue · balanced

0/8 visible results are ready for staged adoption under this preset.

ready 0caution 8hold 0
caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

guides/claude-code-github-actions-review-workflow · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/github-actions-security-review-capability-pack · trust review · confidence 67%

GitHub Actions Validator

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/github-actions-workflow-validator · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/github-artifact-attestation-provenance-capability-pack · trust review · confidence 67%

Open Source PR Security Review Agent

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

agents/open-source-pr-security-review-agent · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

2/8 results are high-confidence for the selected preset.

high 2medium 6low 0

Claude Code GitHub Actions Review Workflow

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

guides/claude-code-github-actions-review-workflow · trust review

GitHub Actions Validator

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

hooks/github-actions-workflow-validator · trust review

Open Source PR Security Review Agent

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

agents/open-source-pr-security-review-agent · trust review

Freshness distribution

Mostly fresh with a few aging entries

Median age 54 days; 5 fresh, 3 aging or stale of 8 scanned.

median 54d

Aging

91–180 days

13%

1 entry

Stale

> 180 days

25%

2 entries

Theme distribution

Results center on github-actions

100% of this view shares the top theme. Leading themes: github-actions, ci-cd, devops.

Focused

22 distinct themes across 8 scanned

GitHub logo

Expert GitHub Actions capability skill for secure workflow architecture, token minimization, supply-chain controls, and CI reliability.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓
GitHub logo

Build intelligent CI/CD pipelines with GitHub Actions, AI-assisted workflow generation, automated testing, and deployment orchestration.

Level:advancedType:generalVerified:draft
Safety ✓ Privacy ✓
GitHub logo

Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓
GitHub logo

Validates GitHub Actions workflow files for syntax errors and best practices.

Trigger:PostToolUse
Safety ✓ Privacy ✓
GitHub logo

Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Slash command that triages a failing GitHub Actions run: it pulls the failed job logs with the GitHub CLI, isolates the first real error, classifies the failure (test, lint, type, build, dependency, or flaky), and proposes a targeted, minimal fix with the exact command to reproduce it locally.

Invocation:/ci-failure-triage [run-id]
Safety ✓ Privacy ✓
GitHub logo

Set up Claude Code GitHub Actions for pull request review: install the Claude GitHub app, store ANTHROPIC_API_KEY in secrets, pin anthropics/claude-code-action to an audited commit SHA with least-privilege permissions, and follow documented security practices.

Source-backed agent for security review of open-source pull requests, including untrusted fork boundaries, GitHub Actions permissions, secret and code scanning, dependency review, provenance signals, and maintainer-owned merge recommendations.