April 23, 2026
RsMetaCheck
Version updated for https://github.com/SoftwareUnderstanding/rs-metacheck-action to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The RsMetaCheck GitHub Action automates the detection of metadata issues in software repositories by leveraging the RsMetaCheck Python tool and SoMEF. It streamlines the identification and analysis of potential metadata pitfalls, enabling developers to improve the quality and compliance of their repository’s metadata. Key capabilities include generating detailed outputs for detected pitfalls, analyzing existing SoMEF results, and supporting customizable thresholds and outputs for metadata evaluation.
April 23, 2026
Helm Kustomize Lint Action
Version updated for https://github.com/somaz94/helm-kustomize-lint-action to version v1.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The helm-kustomize-lint-action is a GitHub Action designed to automate linting and validation tasks for Helm charts and optionally for Kustomize manifests. It simplifies workflows by providing end-to-end linting, rendering, and validation capabilities, including YAML linting, strict Helm linting, Helm template rendering, and optional schema validation via kubeconform. Additionally, it supports monorepos by detecting and processing only changed Helm charts, reducing manual effort and ensuring robust CI/CD pipelines for Kubernetes-related projects.
April 23, 2026
Sprocket CI/CD
Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.24.0.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sprocket GitHub Action integrates the Sprocket CLI tool into CI/CD pipelines, automating the validation, linting, and formatting of WDL (Workflow Description Language) documents. It performs static analysis, schema validation, and ensures proper formatting of WDL files, helping developers maintain code quality and consistency. Key capabilities include customizable linting rules, input schema validation, and configuration synchronization between local and CI environments.
April 23, 2026
Causinator 9000 CI Diagnosis
Version updated for https://github.com/sylvainsf/causinator9000 to version v1.9.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Causinator 9000 is a reactive causal inference engine designed to identify the root cause of infrastructure degradations by analyzing dependency graphs, recent deployment changes, and observed symptoms. It automates the process of tracing causal paths and ranking potential causes using Bayesian inference, temporal decay, and dependency attenuation, providing confidence scores for each candidate. This action helps teams quickly diagnose and resolve issues in complex, interconnected cloud systems while minimizing false positives.
April 23, 2026
compose-lint
Version updated for https://github.com/tmatens/compose-lint to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary compose-lint is a security-focused linter for Docker Compose files that identifies and flags potentially dangerous misconfigurations before deployment. It automates the process of validating configurations against best practices and security standards such as OWASP and CIS, providing developers with actionable insights to improve container security. Designed to be fast, opinionated, and zero-configuration, it helps mitigate risks by catching issues early in the development pipeline.
April 23, 2026
Runner Guard
Version updated for https://github.com/Vigilant-LLC/runner-guard to version v3.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runner Guard is a CI/CD supply chain security scanner designed to detect and mitigate vulnerabilities in GitHub Actions workflows. It automates the detection of pipeline injection attacks, unpinned dependencies, AI configuration poisoning, and supply chain threats, while also scanning dependency pipelines for security issues. Key features include vulnerability reporting, auto-fixing issues, continuous monitoring of dependencies, and generating security scores to enhance workflow integrity.
April 23, 2026
Vercel Deploy Comment
Version updated for https://github.com/wiyco/vercel-deploy-comment to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The “Vercel Deploy Comment” GitHub Action automates the deployment of one or more Vercel projects and updates a single comment in a pull request with the deployment status, environment, and preview links. It solves the problem of managing and tracking multiple Vercel deployments directly from GitHub Actions while maintaining an organized and up-to-date summary within pull requests. Key capabilities include serial updates to comments for multiple projects/environments and integration with the Vercel CLI for seamless deployment workflows.
April 23, 2026
AgentRepoCoach — AI agent codebase health scoring
Version updated for https://github.com/WouterDeBot/AgentRepoCoach to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentRepoCoach is a GitHub Action and CLI tool that evaluates the readiness of a codebase for autonomous AI agents by calculating a composite Codebase Agent Health (CAH) score. It automates the analysis of key aspects like navigability, error quality, decision-making support, testing practices, and module organization, offering actionable insights to improve code maintainability and AI compatibility. This tool helps teams identify and address structural and documentation gaps in their repositories while providing automated thresholds for CI/CD workflows.
April 23, 2026
sentinel MCP Security Scanner
Version updated for https://github.com/Helixar-AI/sentinel to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sentinel MCP Scanner is a security-focused GitHub Action that automates the detection of misconfigurations in Model Context Protocol (MCP) servers, live endpoints, and Docker containers. It performs static and dynamic analyses to identify vulnerabilities, provides severity ratings with remediation guidance, and integrates seamlessly into CI/CD workflows to block pull requests based on critical findings. Key capabilities include comprehensive scanning across multiple modules, customizable output formats, and support for SARIF reporting for GitHub Code Scanning.
April 23, 2026
Unpinched — PinchTab Detector
Version updated for https://github.com/Helixar-AI/Unpinched to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The pinchtab-detector GitHub Action is a security tool designed to scan environments for artifacts and indicators of PinchTab, a stealth browser hijacking toolkit that exploits the Chrome DevTools Protocol for unauthorized access. It automates detection of suspicious processes, open ports, filesystem artifacts, and other signs of PinchTab, providing actionable risk assessments to protect against silent browser session takeovers and AI agent compromise. This tool is particularly valuable for securing environments against threats that bypass traditional endpoint security measures.