July 14, 2026
Cache Go files efficiently
Version updated for https://github.com/capnspacehook/cache-go to version v2.1.1.
This action is used across all versions by 6 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action cache-go helps in efficiently caching Go module and build files. It ensures that cached build files are not invalidated by changes in dependencies and avoids the need to restore a stale cache when a newer version of Go is used. The action uses separate keys for restoring and saving these caches, making it easier to manage different versions and environments.
July 14, 2026
Contrast AI SmartFix
Version updated for https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action to version v1.0.20.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 5 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SmartFix is an AI-powered GitHub Action that automates the remediation of security vulnerabilities identified by Contrast Security. It integrates seamlessly into existing workflows via GitHub Actions, generating Pull Requests (PRs) with proposed fixes. Key benefits include automated remediation, developer-focused PR creation, and accurate vulnerability context. Users can choose from SmartFix’s internal coding agent or integrate with GitHub Copilot or Anthropic’s Claude Code bot for customized vulnerability fixes.
July 14, 2026
mcpfold config gate
Version updated for https://github.com/dj-pearson/MCPFold to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary mcpfold is a CLI that connects every MCP server without incurring the context-window tax by curating toolsets per client. It reduces the number of tokenized tool schema entries by up to 80% and avoids hardcoding secrets by resolving references. The action simplifies configuration management, making it portable across different clients with a single canonical config file.
July 14, 2026
easySFTP
Version updated for https://github.com/eiserv/easySFTP to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action automates secure SFTP file transfers for deploying build output to any SFTP server. It supports fast, secure uploads with options for host key pinning, configurable uploads, delete mode, dry runs, retries, and outputs for monitoring. The action is designed to be simple yet highly customizable, suitable for both small deployments and complex multi-target scenarios.
July 14, 2026
Sieve Security Scan
Version updated for https://github.com/fendora-io/sieve-action to version v1.4.4.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Sieve is a GitHub Action that uses AI-powered security scanning to detect real vulnerabilities in pull requests, with the ability to suppress false positives. The action automatically scans code files and posts relevant comments on PRs, allowing team members to mark findings as either real or false positive. It supports customization via inputs for repo alias and failure behavior during checks.
July 14, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across various Codex, Claude, Gemini, and OpenCode ecosystems for security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata, ensuring compliance with main scanner release train standards. The action supports manual scan, lint, verify, and submit modes, with options to specify plugin directories, execution profiles, output formats, and more.
July 14, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to ensure security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata while staying aligned with the main scanner release train.
July 14, 2026
Alcatraz PII Scan
Version updated for https://github.com/hoophq/alcatraz-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Alcatraz PII Scan GitHub Action detects and reports personal identifiable information (PII) in code, logs, comments, or issues across 12 countries. It uses Alcatraz’s detection engine without any external services or network calls. The action scans PR diffs, log outputs, and comment bodies for PII, annotates the lines, posts a sticky report comment, writes a step summary, and can fail the check until PII is removed or allow-listed.
July 14, 2026
GHAGGA Code Review
Version updated for https://github.com/JNZader/ghagga to version v3.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GHAGGA is a production AI code review system that automates static analysis and multi-agent decision-making processes to improve code quality and maintainability. It uses 17 deterministic tools for detection of known issues before running a large language model (LLM). The tool learns from past reviews, retains context, and supports five orchestration strategies for different review needs.
July 14, 2026
npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The npm-scan action detects various types of supply chain threats, including kernel rootkits, memory extraction, and AI-targeted attacks. It provides 95%+ confidence on real campaigns and is 1,875x more cost-effective than traditional tools like npm audit and Snyk.