July 19, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.8.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight read-only viewer for OpenSpec content that automates tasks such as browsing specs, changes, and tasks with structure. It solves problems related to managing parallel worktrees in AI-agent environments by aggregating all in-flight changes into one view, providing full-text search capabilities, and offering a responsive layout across various screen sizes.
July 19, 2026
runward gate
Version updated for https://github.com/stranxik/runward to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is a tool that automates the verification of engineering decisions made by AI-generated code. It checks whether the architectural, security, and operational aspects were correctly implemented during the development process. By running the deterministic gate, Runward ensures that the load-bearing decisions are accurately recorded and can be verified deterministically without relying on an LLM.
July 19, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.4.
This action is used across all versions by 138 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a dependency manager for TOML files in your GitHub Actions workflows. It allows users to install Tombi and its dependencies efficiently, with options for specifying specific versions, using lock files, enabling checksum verification, and configuring cache behavior.
July 19, 2026
Setup Upwarden
Version updated for https://github.com/upwarden-io/setup-upwarden to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-upwarden GitHub Action automates the authentication and authorization of package manager dependencies, enabling keyless OIDC access to private registries. It ensures that every dependency fetch in a CI pipeline is authenticated, attributed, and policy-enforced, mitigating security risks associated with unauthenticated and unattributed package fetches. The action works seamlessly across various toolchains (npm, pnpm, yarn, pip, maven, gradle) and provides a simple setup process to integrate OIDC authentication into your CI pipelines.
July 19, 2026
Premature Contribution Firewall dry-run
Version updated for https://github.com/VrtxOmega/premature-contribution-firewall to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Premature Contribution Firewall automates the review-readiness assessment of pull requests and patches, helping maintainers prioritize actionable tasks before submission. It ensures that contributions meet key criteria such as reproducibility, scope, testing, and worth human attention, reducing the workload by focusing on issues most likely to be beneficial for the project.
July 19, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the testing of Claude Cowork skills in a headless and CI-friendly manner. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. Key features include:
July 19, 2026
Open License Auditor
Version updated for https://github.com/yanovian/open-license-auditor to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Open License Auditor GitHub Action automates the process of identifying and flagging potentially problematic open source licenses in a repository. It supports various package managers, checks dependencies (direct and indirect), and provides detailed reports about any risky licenses found on pull requests. The action can be configured to filter results based on severity, fail the build if critical issues are detected, and optionally post comments with the audit report.
July 19, 2026
PR Rigor
Version updated for https://github.com/Hassan7253/pr-rigor to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Rigor automates deterministic checks to ensure that pull requests are prepared for focused human review. It identifies missing context, tests, security issues, supply chain problems, release readiness, and compatibility, providing clear evidence and recovery steps. The action is designed to help maintainers keep final authority over pull request acceptance, using repeatable first-pass checks with a stable GitHub comment update.
July 19, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, account takeovers, and over 350 threat indicators across various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and GitHub repositories. It generates CycloneDX 1.6 SBOMs with real dependency inventories, parses and validates in-toto/DSSE attestations, and correlates findings into attack-chain incidents.
July 19, 2026
ASCII profile card
Version updated for https://github.com/hu553in/ascii-profile-card to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats, automating the process of maintaining up-to-date profile information in a dedicated branch. It supports customizable configurations through inline YAML documents and provides dark and light variants for easy integration into profiles. The action ensures that the generated files are updated regularly, enhancing user experience by keeping their profiles fresh.