July 8, 2026
Yandex Cloud Federated IAM Token
Version updated for https://github.com/stat1c-void/yc-fed-iam-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update action to run on Node24 chore: bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/51 chore: bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/50 chore: bump the npm-development group with 7 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/48 chore: bump the actions group with 3 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/49 Full Changelog: https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.5...v1.0.6
July 8, 2026
PollyAction
Version updated for https://github.com/Swevo/PollyAction to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Shortened action description to fit Marketplace’s 125-character limit. No functional changes.
July 8, 2026
Meadows Bundler
Version updated for https://github.com/TeamMeadows/bundler to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/TeamMeadows/bundler/compare/v0.2.1...v0.2.2
July 8, 2026
Agents Shipgate
Version updated for https://github.com/ThreeMoonsLab/agents-shipgate to version v0.15.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agents Shipgate v0.15.0
July 8, 2026
Zyrax Guard
Version updated for https://github.com/tiagosilva07/zyrax-guard to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.11.0 — BLOCK means attack One deliberate verdict-policy change.
⚠️ Changed: vulnerabilities in legitimate packages now WARN instead of BLOCK BLOCK is now reserved for known-malicious packages — typosquats, hallucinated names, denylist and OSV MAL-* malware entries. A vulnerability advisory on a legitimate package (any severity) now yields WARN, with the severity shown in the message:
July 8, 2026
Trigv
Version updated for https://github.com/Trigv/trigv-github-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Optional url input for event destination links When url is omitted, the action automatically sends the current GitHub Actions run URL Default auto-generated description no longer includes the raw workflow URL (it is sent in url instead) Usage uses: Trigv/trigv-github-action@v1.1.0
July 8, 2026
Polder Reach
Version updated for https://github.com/usepolder/reach to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One number for design system adoption.
CLI: npx @usepolder/reach --library "@your/design-system" scores any React repo with zero config. --json emits the versioned report (schemaVersion 1). GitHub Action: uses: usepolder/reach@v1 posts a single PR comment (updated in place) with the score, the delta vs the base branch (computed in a temporary git worktree), and the leak count. Fork PRs degrade to the step summary. Badge, zero infra: pushes to the default branch commit .polder/reach-badge.json (shields.io endpoint schema) plus a static SVG fallback for private repos. Leaks: hardcoded hex colors and px values with file/line locations. The score formula is not configurable. A score you can tune is a score nobody trusts.
July 8, 2026
GitHub Actions Version Audit
Version updated for https://github.com/varunchandak/gh-actions-version-audit to version v1.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refresh Marketplace documentation with the workflow-file PR token requirements.\n- Clarify that commits to PR branches still need workflow-file write permission when modifying .github/workflows.\n- Document Resource not accessible by integration as the expected symptom for insufficient token permissions.
July 8, 2026
Start Wiz Sensor
Version updated for https://github.com/wiz-sec-public/wiz-sensor-github-action to version v0.9.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Print sensor error logs on failure Add a new “generate-support-package” input Add marker, to help verify the action ran with the sensor Upgrade dependencies
July 8, 2026
Local Podcast Generator
Version updated for https://github.com/yeste-rge/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update Dockerfile to install git and modify COPY commands by @yeste-rge in https://github.com/yeste-rge/podcast-generator/pull/1 New Contributors @yeste-rge made their first contribution in https://github.com/yeste-rge/podcast-generator/pull/1 Full Changelog: https://github.com/yeste-rge/podcast-generator/commits/v1.0