April 23, 2026
compose-lint
Version updated for https://github.com/tmatens/compose-lint to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary compose-lint is a security-focused linter for Docker Compose files that identifies and flags potentially dangerous misconfigurations before deployment. It automates the process of validating configurations against best practices and security standards such as OWASP and CIS, providing developers with actionable insights to improve container security. Designed to be fast, opinionated, and zero-configuration, it helps mitigate risks by catching issues early in the development pipeline.
April 23, 2026
Runner Guard
Version updated for https://github.com/Vigilant-LLC/runner-guard to version v3.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runner Guard is a CI/CD supply chain security scanner designed to detect and mitigate vulnerabilities in GitHub Actions workflows. It automates the detection of pipeline injection attacks, unpinned dependencies, AI configuration poisoning, and supply chain threats, while also scanning dependency pipelines for security issues. Key features include vulnerability reporting, auto-fixing issues, continuous monitoring of dependencies, and generating security scores to enhance workflow integrity.
April 23, 2026
Vercel Deploy Comment
Version updated for https://github.com/wiyco/vercel-deploy-comment to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The “Vercel Deploy Comment” GitHub Action automates the deployment of one or more Vercel projects and updates a single comment in a pull request with the deployment status, environment, and preview links. It solves the problem of managing and tracking multiple Vercel deployments directly from GitHub Actions while maintaining an organized and up-to-date summary within pull requests. Key capabilities include serial updates to comments for multiple projects/environments and integration with the Vercel CLI for seamless deployment workflows.
April 23, 2026
AgentRepoCoach — AI agent codebase health scoring
Version updated for https://github.com/WouterDeBot/AgentRepoCoach to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentRepoCoach is a GitHub Action and CLI tool that evaluates the readiness of a codebase for autonomous AI agents by calculating a composite Codebase Agent Health (CAH) score. It automates the analysis of key aspects like navigability, error quality, decision-making support, testing practices, and module organization, offering actionable insights to improve code maintainability and AI compatibility. This tool helps teams identify and address structural and documentation gaps in their repositories while providing automated thresholds for CI/CD workflows.
April 23, 2026
sentinel MCP Security Scanner
Version updated for https://github.com/Helixar-AI/sentinel to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sentinel MCP Scanner is a security-focused GitHub Action that automates the detection of misconfigurations in Model Context Protocol (MCP) servers, live endpoints, and Docker containers. It performs static and dynamic analyses to identify vulnerabilities, provides severity ratings with remediation guidance, and integrates seamlessly into CI/CD workflows to block pull requests based on critical findings. Key capabilities include comprehensive scanning across multiple modules, customizable output formats, and support for SARIF reporting for GitHub Code Scanning.
April 23, 2026
Unpinched — PinchTab Detector
Version updated for https://github.com/Helixar-AI/Unpinched to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The pinchtab-detector GitHub Action is a security tool designed to scan environments for artifacts and indicators of PinchTab, a stealth browser hijacking toolkit that exploits the Chrome DevTools Protocol for unauthorized access. It automates detection of suspicious processes, open ports, filesystem artifacts, and other signs of PinchTab, providing actionable risk assessments to protect against silent browser session takeovers and AI agent compromise. This tool is particularly valuable for securing environments against threats that bypass traditional endpoint security measures.
April 23, 2026
EvalView - AI Agent Testing
Version updated for https://github.com/hidai25/eval-view to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EvalView is an open-source GitHub Action designed to detect and manage silent regressions in the behavior of AI agents, such as changes in tool usage, output quality, or decision-making processes. It automates tasks like tracking behavior drift, classifying changes, and facilitating safe auto-healing of issues, providing graded confidence levels instead of binary alarms to distinguish between provider/model updates and actual regressions. This tool empowers developers and teams to ensure their AI agents continue to function correctly and reliably without requiring extensive resources.
April 23, 2026
Hyperlocalise CI
Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Hyperlocalise GitHub Action automates localization workflows by integrating with CI pipelines to streamline translation management for modern applications. It provides functionality to detect localization changes (drift) and validate translation integrity (check) using the Hyperlocalise CLI, offering reporting, annotation, and artifact upload capabilities. This action eliminates manual localization processes, making it easier to maintain accurate and consistent translations directly within engineering workflows.
April 23, 2026
Versionary Action
Version updated for https://github.com/jolars/versionary to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Versionary is an automated release tool designed to streamline version management, changelog generation, tagging, and release workflows across diverse ecosystems while adhering to semantic versioning and conventional commits. It supports both direct releases and release-PR workflows, enabling maintainers to review changes before publication. By centralizing versioning and release metadata tasks, it eliminates the need for manual intervention, leaving artifact publication to CI/CD systems triggered by tags or releases.
April 23, 2026
Bulk GitHub Repository Settings Sync
Version updated for https://github.com/joshjohanning/bulk-github-repo-settings-sync-action to version v2.7.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the bulk synchronization of repository settings and files across multiple repositories, streamlining administrative tasks for organizations. It addresses common challenges such as managing pull request settings, enabling security features, and syncing configuration files (e.g., .gitignore, dependabot.yml, workflow files) across repositories while allowing for dynamic targeting and per-repository overrides. Key capabilities include dry-run previews, intelligent change detection, and comprehensive logging to ensure accurate updates.