July 9, 2026
MCP Trust Scan
Version updated for https://github.com/SteveMonsway/mcp-trust to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One-line MCP-server preflight scan in CI — the root composite Action.
```yaml
uses: actions/checkout@v4 uses: SteveMonsway/mcp-trust@v1 with: { fail-on: high, upload-sarif: true, comment-pr: true } ``` Runs the published @mcp-trust/cli via `npx` (self-contained, no build). Uploads SARIF to Code Scanning, posts a PR comment, and fails the job above a severity threshold.
July 9, 2026
LLM Prompt Radar
Version updated for https://github.com/Tahiram32/llm-prompt-radar to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s New in v0.2.0 YAML/TOML config file support (.promptradar.yml) LangChain and LlamaIndex SDK support Custom rule definitions (bring-your-own regex) PR comment posting with risk summary table Pre-commit hook integration VS Code extension skeleton pip install --upgrade llm-prompt-radar PyPI: https://pypi.org/project/llm-prompt-radar/0.2.0/
July 9, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.18.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.18.0 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/35 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.3...v0.18.0
July 9, 2026
latex2arxiv pre-flight
Version updated for https://github.com/YuZh98/latex2arxiv to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Pre-flight warns when a shipped .bbl has a bbl format version arXiv won’t accept (3.2 needs the soon-to-retire TL2023; anything else needs regeneration), when a BibTeX-format .bbl is paired with a biblatex document, and when a bundled biblatex.sty is included in the submission Changed Citation scan now recognizes the biblatex cite families (\autocite, \parencite, \textcite, \footcite, \nocite, capitalized and multicite forms) and pre/post-note optional arguments; the undefined-citation check reads biblatex-format .bbl files (\entry{...}) in addition to \bibitem Fixed \addbibresource[options]{...} is now recognized by dependency tracking, pre-flight, and the --compile biber dispatch; the functional biblatex keywords field is no longer stripped from .bib files in biblatex projects VS Code extension (0.1.2): the new biblatex pre-flight warnings are located in the editor — .bbl format/backend warns anchor the .bbl file itself, the bundled-biblatex.sty warn anchors the .sty Dependency tracking resolves \input/\include in nested files against the compile root (LaTeX semantics) and keeps non-.tex targets such as .pgf figures; both were previously pruned from the output (#229) Custom config rules no longer match longer commands sharing a prefix (an hl rule used to corrupt \hline) (#229) The hidden-file pre-flight warning is emitted once per dot-directory instead of once per contained file (#229)
July 8, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.10.0 (2026-07-08) GitLost-class agentic-workflow posture detection
Closes the gap surfaced by Noma Security’s “GitLost” disclosure (July 2026): an AI agent driven by a GitHub workflow can be prompt-injected through an untrusted issue/PR into leaking private-repo data via a public comment. The runtime attack is GitHub’s to fix; what is static and checked-in is the vulnerable POSTURE, and that is now scannable before an attacker files the issue.
July 8, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: add A2A protocol security support (v2.6.0) (1b99a1b) fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688) chore: replace all example.com targets with simpleportchecker.com (676106d) fix: –format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8) fix: skip –timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd) chore: use Gemini public endpoint in ai-owasp-scan job (6a13857) fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41) fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327) chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12) fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)
July 8, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.4
July 8, 2026
MLX Model Doctor
Version updated for https://github.com/IonDen/mlx-model-doctor to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Prepare v0.7.0 reach/readiness and VLM plugin release by @IonDen in https://github.com/IonDen/mlx-model-doctor/pull/23 Full Changelog: https://github.com/IonDen/mlx-model-doctor/compare/v0.6.2...v0.7.0
July 8, 2026
🚀 React Template CI/CD
Version updated for https://github.com/Jagoda11/react-template to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add Claude Code setup: CLAUDE.md + .claude/settings.json with permissions, hooks, plugins Rename lint step in npm-upgrade workflow (drop misleading “non-blocking” label) Compatibility Node 24.x ESLint 9.x
July 8, 2026
Official Junie GitHub Action
Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Junie]: Update Junie CLI Version to 2144.8 in Files by @mashan555 in https://github.com/JetBrains/junie-github-action/pull/174 Full Changelog: https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.8