Below you will find pages that utilize the taxonomy term “GitHub Actions”
July 24, 2026
rs-cargo
Version updated for https://github.com/clechasseur/rs-cargo to version v5.0.7.
This action is used across all versions by 303 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs specified cargo commands on a Rust project. It automates the execution of common tasks such as building and testing, and provides transparent support for cross-compilation through optional tools like cross or cargo-hack.
July 24, 2026
check-version-before-release
Version updated for https://github.com/digicatapult/check-version to version v1.5.94.
This action is used across all versions by 35 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action compares versions in project manifests and checks they are higher than the latest published tag, supporting npm, Cargo, and Poetry package managers. It uses GitHub API tokens to access tags and supports filtering tags with a regular expression. If the local version matches the latest published tag, it can either fail or return a boolean indicating if it’s a new version.
July 24, 2026
Pull request bot synchronizes two services GitHub, Moodle. Script 1
Version updated for https://github.com/Dmitriy129/moodle-github-sync-1 to version test.0.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The moodle-github-sync-1 GitHub Action automates the synchronization of Moodle themes and plugins with their corresponding files on GitHub. It solves the problem of maintaining and updating Moodle resources by allowing developers to push changes from local repositories directly to the remote repository, ensuring consistency across different development environments and platforms.
July 24, 2026
sealed-build
Version updated for https://github.com/EngineerSamet/sealed-build to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds a container image and produces an SBOM, refuses to push it if it fails a vulnerability threshold, and signs the result with keyless attestation using pinned commit hashes, ensuring security by maintaining immutable evidence. It addresses trust issues in the supply chain by preventing malicious pushes through mutable tags.
July 24, 2026
Plumber Score
Version updated for https://github.com/getplumber/plumber to version v0.4.16.
This action is used across all versions by 44 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Plumber is an open-source CI/CD security scanner that uses a Rego policy engine to scan .gitlab-ci.yml and .github/workflows/*.{yml,yaml} files. It helps identify risky patterns and security gaps in CI/CD pipelines, providing comprehensive reports in various formats such as terminal, JSON, SARIF, GitLab SAST, PBOM, and CycloneDX.
July 24, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Supply-chain Guard is an open-source tool designed to scan and analyze dependency chains across various package managers and ecosystems, including npm, Pypi, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It detects malware campaigns (e.g., GlassWorm, Vidar), fake AI tool repos, account takeovers, and numerous threat indicators across multiple lockfile formats. The action generates CycloneDX SBOMs, validates SLSA provenance, and correlates findings into attack-chain incidents for enhanced security awareness and remediation.
July 24, 2026
Redflag Secret Scanner
Version updated for https://github.com/iammerus/redflag to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Redflag is a cross-platform CLI that scans source files and Git history for secrets using regular-expression rules and heuristic Shannon entropy checks. It helps automate the detection of sensitive information, such as passwords and API keys, in both codebases and version control systems. The action integrates with GitHub Actions to perform secret scanning in CI pipelines.
July 24, 2026
MCP Trust Checker — MCP Security Scan
Version updated for https://github.com/illiahaidar/mcptrustchecker to version 1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCP Trust Checker is a deterministic security scanner that assesses Model Context Protocol servers to ensure they are safe before connecting them to data. It uses the Capability-Flow Trust Model, an original algorithm, to evaluate servers based on their roles and behavior, identifying threats such as untrusted input ingress, sensitive data sources, and exfiltration paths, ensuring they do not pose a risk.
July 24, 2026
droast — Dockerfile linter
Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary droast is an opinionated Dockerfile linter that catches bad practices and reports them in a blunt manner. It supports various features such as parsing heredocs, handling parser directives, shell forms, BuildKit flags, Windows paths, and PowerShell, and provides real-time feedback with inline squiggles in VS Code and lint-on-save for Neovim users.
July 24, 2026
Aeroflare CI
Version updated for https://github.com/ItzEmoji/aeroflare to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: The GitHub Action ItzEmoji/aeroflare@v1 automates the process of building and pushing Nix packages to an OCI cache, providing a stateless, zero-infrastructure binary substituter. It supports pushing builds directly from CI without requiring additional tooling on the host machine. The action can build all outputs or specific ones based on changes or specified patterns, making it suitable for continuous integration workflows where Nix is used for packaging and caching dependencies.
July 24, 2026
stackit-cli tools installer
Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.92.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a specific version of the stackit-cli tool on a runner, allowing developers to automate the setup and use of stackit-cli in their workflows. It supports fetching either the latest stable release or any specified semantic version, making it easy to integrate stackit-cli into CI/CD pipelines for deployment and management tasks.
July 24, 2026
Kusari Ingest
Version updated for https://github.com/kusaridev/kusari-ingest to version v4.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading SBOMs, SLSA attestations, and other artifacts to the Kusari Platform from a GitHub workflow. It simplifies integration by handling authentication credentials and provides options to generate SBOMs automatically or manually. Key features include capturing ingestion results for machine-readable IDs and ensuring components are mapped if needed.
July 24, 2026
Lingo.Dev AI Localization
Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.3.
This action is used across all versions by 107 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action is designed to automate the continuous localization process within a repository using the Lingo.dev platform. It helps teams manage translations efficiently and ensure consistency across multiple locales, reducing errors by leveraging AI-assisted tools and connecting directly to translation APIs.
July 24, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary lgtmaybe is a GitHub Action that reviews pull requests by analyzing code changes and security vulnerabilities, providing inline comments and summaries on GitHub. It uses an OpenAI-compatible model to generate feedback without checking out or running the code, focusing on logic errors, security risks, tests, documentation updates, performance issues, complexity, intent, and unnecessary complexity. The action can run in different presets for varying levels of thoroughness, including default fast mode and full audit mode for release branches.
July 24, 2026
vuln.mlab.sh SBOM scan
Version updated for https://github.com/mlab-sh/vuln-scan-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of dependency lockfiles in a repository for known CVEs using vuln.mlab.sh. It automatically detects common lockfile types and checks each package against OSV and Sonatype OSS Index, providing detailed vulnerability reports in the job summary. The action can fail the build based on a specified severity threshold or report vulnerabilities without failing, with outputs for total vulnerabilities, vulnerable packages, and failure status.
July 24, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.32.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a specific Go module proxy cache when new tags are created, ensuring that the latest module versions are immediately available and documentation is updated on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version used for building the module.
July 24, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.24.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action automates running Apex tests locally, providing a fast feedback loop without using an org or deploy. It supports running unit tests with code coverage and executing anonymous Apex, as well as debugging Apex in interactive mode through VS Code or IntelliJ. The action can be installed via Homebrew, the Salesforce CLI, or manually downloaded and added to the PATH.
July 24, 2026
Automatic Semantic Releases
Version updated for https://github.com/oliversalzburg/action-automatic-semantic-releases to version v3.3.1.
This action is used across all versions by 16 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, designed by oliversalzburg, automates the creation of semantic releases. It helps maintain consistency in version numbers and release processes across projects. The action supports both tagged builds and automatic releases on pushes or schedules, ensuring that versions are managed correctly without manual intervention.
July 24, 2026
Directory Listing Generator
Version updated for https://github.com/pranabdas/directory-listing to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates directory listings for a repository’s files and directories and automates their automatic deployment to a specified branch, either within the same repository or an external repository using personal access tokens. The action is useful for creating static websites directly from a GitHub repository without additional setup, and it supports various configuration options such as excluding certain files, setting custom site URLs, and managing publishing directories.
July 24, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.36.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README facilitates automated security assessments within cloud environments using Prowler, an Open-Source Cloud Security Platform. It simplifies the process of conducting real-time monitoring and customizable vulnerability scans, ensuring organizations can maintain a secure and compliant state across multiple cloud platforms.
July 24, 2026
ECS Exec
Version updated for https://github.com/risk3sixty/ecs-exec to version v2.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows developers to execute a command in the specified ECS Fargate Service. It automates database migrations by running scripts directly within the service containers, reducing the need for manual intervention and improving efficiency. The action handles multiple container services by requiring a specific container name when necessary, ensuring consistent execution across all tasks within the service.
July 24, 2026
SFDT for Salesforce
Version updated for https://github.com/scoobydrew83/sfdt to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and release management of Salesforce projects using the @sfdt/cli tool. It simplifies the process by providing features such as interactive workflows with preflight validation, automated release manifests, parallel Apex test execution, AI-powered fix plans for code and tests, and CI/CD pipeline templates for GitHub, GitLab, Azure, and Bitbucket. The action also supports multi-package projects and provides a local web dashboard for monitoring and comparing org states.
July 24, 2026
Reelier replay
Version updated for https://github.com/seldonframe/reelier to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Reelier automates the verification of AI agent tool-call workflows against new dependencies, ensuring consistency and reliability in software development processes. By replaying recorded runs at zero LLM cost and diffing them, Reelier helps identify any drift between the original run and the updated environment, providing clear receipts for audits and approvals before merging changes.
July 24, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.28.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI code review tool that optimizes recall to find more real bugs while keeping false positives manageable. It runs multiple specialized AI reviewers in parallel and uses an evidence-based curator to verify findings before posting review comments on GitHub pull requests. The planner briefs every reviewer up front, lenses focus on specific problem domains, and the curator merges duplicates and only dismisses issues with cited quotes from the diff.
July 24, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: SSG is a fast Go-based static site generator that converts Markdown with YAML frontmatter into a complete website. It supports various features such as built-in themes, templates engines, SEO metadata, image processing, and deployment to multiple platforms like GitHub Pages, Netlify, Vercel, and more. The action automates content generation, rendering, and deployment processes, making it ideal for blog creation, documentation, and other static site needs.
July 24, 2026
KCD Pak
Version updated for https://github.com/tkhquang/kcd-pak-action to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action packages a Kingdom Come: Deliverance loose-file mod into game-ready .pak files and a release .zip. It solves the problem of loading mods by ensuring that the paks do not have unnecessary modification-time metadata, which 7-Zip / WinRAR / WinZip add. The action supports both compression methods (deflate or store) and provides outputs for the mod ID and version, allowing users to manage their releases from the mod.manifest file.
July 24, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v10.5.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the universal AI integration platform that simplifies integrating 30+ AI providers and models into applications. It provides a TypeScript-first interface that supports various functionalities such as text streaming from LLM providers, handling different output modes (avatar and music), and deploying with enterprise features like Redis memory and failover. The action automates these tasks and streamlines the integration process for developers.
July 24, 2026
Agent Diff Guard
Version updated for https://github.com/jwa-wa/agent-diff-guard to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks AI agent configurations to catch risky changes such as safety instructions removal, dangerous tool permissions addition, and model tier swaps. It automates these checks before merging changes into a repository, providing detailed reports and alerts for sensitive configuration modifications. The action supports free and Pro tiers with varying features and reporting options, making it suitable for both casual users and organizations requiring more advanced observability.
July 24, 2026
pr-sage AI Review
Version updated for https://github.com/Kyeom1997/pr-sage to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary pr-sage is an AI-powered pull request reviewer designed to minimize noise and follow team conventions. It reviews only the most recent changes since the last review, uses fingerprinting to eliminate duplicate comments, and can enforce severity levels and quality gates in PRs. The action supports multiple providers (Anthropic, OpenAI, Gemini) and can be used locally for pre-push reviews without needing a GitHub token.
July 24, 2026
Linear Release
Version updated for https://github.com/linear/linear-release-action to version v0.14.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 90 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @linear/release-action GitHub Action automates the synchronization of deployments with Linear releases by integrating CI/CD pipelines into Linear’s release management system. It scans commits for Linear issue identifiers and pull request references, creating or updating releases in Linear automatically. This action helps teams manage releases more efficiently by ensuring that all related issues are linked to the correct releases.
July 24, 2026
Git Velocity Analyser
Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.13.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your code contributions and generates a game-like dashboard to track developer velocity. It automates the process of analyzing repositories, calculating scores and achievements, and providing insights into team activity patterns. The action supports local Git analysis, caching, and authentication options, making it fast and flexible for developers to monitor their contribution velocity effectively.
July 24, 2026
GitHub Milestones → Jira Epics
Version updated for https://github.com/malparty/gh-milestones-to-jira-epics-action to version 1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action mirrors repository milestones into Jira epics, ensuring one-way synchronization. It maintains an idempotent and safe operation, handling both scheduled runs and manual triggers. The action updates the epic’s summary, description, due date, and labels as needed, while preserving existing manual edits in Jira.
July 24, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The lgtmaybe GitHub Action reviews PRs by analyzing code changes and surrounding lines to identify potential issues such as logic errors, security vulnerabilities, and missing tests. It provides inline review comments and a summary of findings, helping reviewers focus on the most critical changes in context. The action supports multiple review levels (info through critical) and can be configured to run different presets based on branch status.
July 24, 2026
move-test-gen coverage check
Version updated for https://github.com/mehvetero/move-test-gen to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The move-test-gen GitHub Action is an Agent Skill that automatically generates edge-case test suites for Sui Move functions. It focuses on covering various edge cases such as boundary values, arithmetic edges, access control issues, state machine problems, and economic concerns, providing a comprehensive set of tests to ensure robustness in Move smart contracts. The action can be used to generate tests based on user requests or automatically check the coverage of existing tests to identify potential gaps.
July 24, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.105.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a tool that keeps project lessons and rules in the repository itself, ensuring architectural integrity by preventing re-inventing standard patterns. It uses a file-based toolkit with plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules enforced by a local, deterministic zero-LLM linter. This approach reduces friction and improves code quality by preventing common architectural mistakes.
July 24, 2026
MotionScore Guard
Version updated for https://github.com/motiondivision/motionscore-guard to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MotionScore Guard automates animation performance auditing for pull requests by loading pages in a real browser on GitHub runners and grading them with S to F tiers. It supports free access for any repository but provides a paid plan with token-based gating that fails builds if page grades fall below specified thresholds. The action can audit specific paths and upload reports, making it easy to integrate into workflows.
July 24, 2026
repro-check runnability
Version updated for https://github.com/nelsonjordanme/repro-check to version v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The repro-check GitHub Action automates the process of running and troubleshooting old research code, helping to identify and fix issues such as missing files, outdated dependencies, and removed APIs. It provides a runnability scaffold for reproducing computational papers by finding scripts, attempting to run them, and applying known fixes until they either run successfully or provide detailed information on where they stopped and what needs to be done next.
July 24, 2026
LinkML (linkml-scala)
Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.11.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, linkml-scala-action, automates the validation and generation of LinkML schemas in CI using Node.js. It leverages the @neverblink/linkml npm package to validate schemas by linting them or generating various output formats such as JSON Schema, SHACL, RDF/SDLC, and Scala classes. Key features include inline annotations for GitHub checks, fast execution times, and support for importing additional schema files. The action is designed to be lightweight and compatible with any Node.js runner environment.
July 24, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.16.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that audits AI harness files to ensure they are well-organized, up-to-date, and effective. It helps teams consolidate scattered guidance into a single AGENTS.md file while measuring improvements in agent answers, reducing latency, and optimizing costs. The action checks for inconsistencies, overlapping instructions, declaration-vs-code mismatches, and conflicts across various agent-config files.
July 24, 2026
NetBird CLI Connect
Version updated for https://github.com/NomisCZ/netbird-cli-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of connecting to a NetBird network as an ephemeral peer, enabling access to internal services or databases over a secure WireGuard mesh. It allows users to configure various parameters such as setup keys, management URLs, and DNS settings to facilitate seamless connectivity. The action also provides an option to wait for the local NetBird DNS resolver to be ready before proceeding with subsequent steps, which is useful for ensuring proper resolution of private resources.
July 24, 2026
Directory Listing Generator
Version updated for https://github.com/pranabdas/directory-listing to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action generates directory listings for GitHub Pages and automates the deployment process using GitHub Actions. It supports generating listings from a specified folder, excluding files or directories, and deploying them to either the same repository’s gh-pages branch or an external repository. The action can also customize various aspects such as site URL, base path, site name, footer text, and commit messages.
July 24, 2026
Wrangler Deploy
Version updated for https://github.com/risu729/wrangler-deploy-action to version v1.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of Cloudflare Workers through GitHub Actions, providing a consistent workflow for preview, dry-run, and production deployments. It leverages Wrangler to manage worker deployments and outputs relevant information about the deployment to the GitHub Actions job summary. The action handles authentication credentials and ensures that only qualified users can deploy production workers.
July 24, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.42.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter written in Rust. It offers over 77 lint rules, automatic formatting with the --fix option, and support for multiple Markdown flavors. The action provides detailed error reporting and is optimized for speed, making it suitable for use in CI/CD pipelines and editor integrations.
July 24, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents that schedules tasks in plain Python and ensures reproducibility and auditability. It uses an always-on lineage spine to track changes and an HMAC-chained audit log to verify results offline, making it suitable for environments with strict requirements on transparency and repeatability.
July 24, 2026
Setup UniRTM
Version updated for https://github.com/snowdreamtech/setup-unirtm to version v0.6.0.
This action is used across all versions by 36 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-unirtm automates the installation and configuration of UniRTM, a runtime and tools manager. It intelligently detects the best install method based on available runtimes and supports multiple methods such as npm, pip, GitHub Releases, and go installs. The action also offers features like caching using Handlebars templates and supports GitHub proxy configurations for restricted networks.
July 24, 2026
DLP Secret Scan
Version updated for https://github.com/SpiderCob/dlp-scan-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses dlp-patterns to scan a codebase for secrets, PII, and sensitive data. It helps detect over 50 categories of sensitive information and provides detailed reports on findings, including the number and severity levels. The action can be configured to focus only on API keys and credentials or to scan everything, including PII. Users can set thresholds for severities to trigger different actions in CI/CD pipelines.
July 24, 2026
Install bashunit
Version updated for https://github.com/TypedDevs/bashunit to version 0.43.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a simple testing framework for Bash scripts that automates the process of writing and running tests. It focuses on providing developers with a lightweight, fast testing experience with over 70 assertions across various families, including equality, strings, exit codes, numeric checks, arrays, file/directory permissions, JSON assertions, date comparisons, duration checks, snapshots, and test doubles. The framework is designed to be user-friendly and developer-centric, offering interactive learning through the learn command and extensive documentation at bashunit.com.
July 24, 2026
MCP Test Harness
Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The MCP Test Harness is a CI tool that automates and tests the correctness of MCP servers. It helps teams ensure their AI server features do not break silently and provides evidence of compliance with standards like JUnit, SARIF, and HTML reports. By using this action, developers can quickly verify the reliability and performance of their MCP servers before they are deployed, reducing costs associated with quality assurance and improving overall trust in their codebase.
July 24, 2026
Symfony Security Auditor
Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.17.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered security auditor for Symfony applications that automates the detection of application-level vulnerabilities missed by traditional SAST tools. It targets business logic flaws and multi-file attack chains, providing a comprehensive validation report in console, JSON, SARIF, HTML, or Markdown formats. The action uses adversarial “Attacker” and skeptical “Reviewer” agents to identify and cull false positives over three iterations, ensuring a validated report for security audits in Symfony projects.
July 24, 2026
RustScript Action
Version updated for https://github.com/VladasZ/rustscript to version v0.2.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets and runs Rust scripts without compiling them fully. It allows users to execute Rust code directly from the command line, bypassing the need for Cargo or type checking. The action supports running scripts, validating them without execution, building native binaries, listing supported features, clearing caches, and updating releases.
July 24, 2026
Legion Runner
Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.43.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source security tool that hardens GitHub Actions against supply chain attacks by monitoring outbound connections, blocking unauthorized destinations, and identifying processes behind them. It provides a comprehensive defense mechanism that runs on pure Node built-ins without dependencies and offers features like egress policy control, process attribution, and file integrity checks.
July 24, 2026
vibecheck-ai-slop
Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is a tool that automates the detection of AI-generated code smells by using ESLint rules to identify common issues such as hardcoded secrets, empty catch blocks, and SQL injection vulnerabilities. It runs locally without requiring any external dependencies or configuration files. The main purpose of vibecheck is to help developers quickly identify potential problems in their AI-generated codebases, ensuring better security, maintainability, and performance.
July 24, 2026
Devr Codeguard
Version updated for https://github.com/devr-tools/codeguard to version v1.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary codeguard is a comprehensive tool that automates various repository checks across code quality, design boundaries, security, CI/CD hygiene, AI prompt governance, and repo-specific policy rules. It supports extensive capabilities such as repository exclusions, baselines, waivers, changed-lines diff scans, SARIF output, GitHub annotations, custom rule packs, natural-language custom rules through an optional AI runtime, policy profiles, scan caching, doctor checks, rule discovery from the CLI, native TypeScript/Python quality, design, and security heuristics, and language-specific command checks.
July 24, 2026
check-version-before-release
Version updated for https://github.com/digicatapult/check-version to version v1.5.93.
This action is used across all versions by 35 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action compares the versions in package.json and package-lock.json with those of Cargo.toml and pyproject.toml, ensuring they are higher than the latest published tags for each manager. It also provides a way to set custom paths for these files and handle failed checks by setting a fail_on_same_version flag.
July 24, 2026
easySFTP
Version updated for https://github.com/eiserv/easySFTP to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary easySFTP is a fast, secure, and user-friendly GitHub Action for deploying files to an SFTP server. It handles common deploy tasks with minimal configuration and can be expanded for more complex deployments using a config file. The action supports multiple deployment targets, various authentication methods, and advanced features like file skipping, deletion guards, and performance tuning.
July 24, 2026
Fallow - Codebase Intelligence
Version updated for https://github.com/fallow-rs/fallow to version v3.9.1.
This action is used across all versions by 349 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static code analysis for TypeScript and JavaScript projects by identifying unused files, circular dependencies, duplication, complexity hotspots, boundary violations, and design-system styling drift. It provides deterministic findings with typed output contracts and can be integrated into CI workflows to ensure code quality before deployment. The action supports various formats and integrates with popular development tools like LSP servers for language-specific analysis.
July 24, 2026
opseclint detection-coverage
Version updated for https://github.com/Gerrrt/opseclint to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary opseclint is a detection-coverage analyzer that identifies and analyzes the detectability of command-line actions, scripts, or post-exploitation playbooks against various operating systems (Linux/Auditd, Windows/Sysmon, macOS/Endpoint Security) by resolving them to MITRE ATT&CK techniques, telemetry events, and expected detections. It helps developers understand how their actions would be detected if executed in a real-world environment.
July 24, 2026
trigger-tree docs discoverability gate
Version updated for https://github.com/Hedde/trigger_tree to version v1.24.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary trigger-tree is a local tool that records discovery evidence to improve documentation quality by monitoring which AI coding assistants are accessing project documentation. It helps identify patterns, guardrails, and areas of improvement in the documentation process without relying on cloud analytics or model tokens. The action supports various platforms and provides insights into the health and effectiveness of documentation for teams.
July 24, 2026
Amino Email Deliverability Audit
Version updated for https://github.com/hireamino/amino-audit-action to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action audits the email-authentication posture of sending domains to ensure they meet best practices, such as SPF, DKIM, and DMARC. It provides a detailed audit report in the job summary and allows users to set severity thresholds to fail builds on regressions. The action is read-only and runs on any runner OS.
July 24, 2026
stackit-cli tools installer
Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.90.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of the stackit-cli binary on GitHub Actions runners, allowing users to specify a version (latest or a specific semantic version) and cache the installed binary for future use. The action also prepends the cached binary path to the PATH environment variable, making it accessible in subsequent steps of the workflow.
July 24, 2026
Codex Review Gate
Version updated for https://github.com/JoeyTeng/codex-review-gate-action to version v1.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Review Gate GitHub Action ensures that a PR head has clean Codex review output before passing as a required status check, using Codex’s generative AI capabilities to review pull requests. It maintains a thin workflow in .github/workflows/codex-review-gate.yml and coordinates with GitHub comments, reviews, reactions, and commit statuses for reliable checks.
July 24, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v10.5.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the AI integration platform that provides a single, consistent API for 30+ AI providers and 100+ models. It enables developers to integrate AI into any application with a TypeScript-first approach. Key features include multi-provider failover, intelligent routing, and built-in tools. Users can switch providers with a single parameter change.
July 24, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.97.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scan and reporting of security vulnerabilities across AI, cloud infrastructure, and tools. It helps centralize evidence and enforce runtime calls, providing a single Finding with a UnifiedGraph model accessible from CLI, API, UI, and MCP. The action supports scanning from CLI, CI, Docker, or cloud connections on a custom control plane, allowing for comprehensive visibility into security risks across various environments.
July 24, 2026
Lambda MicroVM GitHub Runner
Version updated for https://github.com/neebs12/lambda-microvm-github-runner to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lambda MicroVM GitHub Runner is an action designed to run GitHub Actions jobs on AWS Lambda using MicroVMs, providing a way to extend Lambda’s 8-hour execution time by utilizing the lightweight nature of MicroVMs. This tool automates the setup and teardown of AWS resources required for running these actions, including creating IAM users, roles, and logs. It also supports configuring containerized workflows inside the runner, making it suitable for multi-container applications.
July 24, 2026
Project Vault Action
Version updated for https://github.com/nestormata/vault-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action retrieves secrets from Project Vault and exports them as masked environment variables in a workflow. It automates the retrieval of secrets scoped to specific projects using machine-user API keys, ensuring that each secrets input refers to the same project, and provides options for handling errors gracefully. The action does not implement its own HTTP client or token exchange logic.
July 24, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.31.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically pulls new versions of Go modules when tags are created, ensuring that your module is immediately available and up-to-date on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of proxy configuration, import paths, and Go versions. The action is triggered by release events and uses the actions/setup-go toolchain for setup.
July 24, 2026
pirafrank/notion-to-jekyll
Version updated for https://github.com/pirafrank/notion-to-jekyll to version v2.
This action is used across all versions by 3 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts Notion pages to Jekyll markdown files, extracting properties such as category and tags. It also downloads block assets like images and files from Notion, ensuring SEO compatibility by adding necessary front matter to posts. The action is designed to be run in a GitHub Actions workflow and can be customized via environment variables for different configurations.
July 24, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of setting up a new API repository by bootstrapping a Postman workspace, uploading an OpenAPI specification, generating test collections, and syncing them with the repository. It also creates CI workflows to rerun tests on every push, pull request, and schedule. The action is designed to provide comprehensive, executable testing solutions for APIs in GitHub repositories.
July 24, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.19.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It also includes dynamic contract tests that cover various protocols such as gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of the broader Postman API Onboarding suite and requires either a public HTTPS URL or a file path to the spec in the repository.
July 24, 2026
Postman Onboarding GCP Spec Discovery
Version updated for https://github.com/postman-cs/postman-gcp-spec-discovery-action to version v1.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Postman Onboarding: GCP Spec Discovery, automates the discovery and export of OpenAPI specifications from Google Cloud services such as GCP APIs and Apigee proxies. It can automatically resolve a specification based on repository context or labels if available, or explicitly specify an API ID for a known configuration. The action uses Application Default Credentials (ADC) or Workload Identity Federation for authentication and supports exporting every candidate specification to facilitate Postman onboarding processes.
July 24, 2026
SFDT for Salesforce
Version updated for https://github.com/scoobydrew83/sfdt to version ext-v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and quality analysis of Salesforce changes using the @sfdt/cli tool. It provides features like interactive deployment workflows, automated release manifest generation, parallel Apex test execution, code quality analysis with AI-powered fix plans, pre-release validation checklist, and multi-package project support.
July 24, 2026
Shipi18n Auto Translate
Version updated for https://github.com/Shipi18n/shipi18n-github-action to version v1.3.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically translates i18n locale files in a repository using the Shipi18n platform. It supports multiple languages, placeholder preservation, and incremental translation, automating the process of maintaining internationalized content. The action also generates pull requests for review and self-corrects failed translations.
July 24, 2026
soroush-bench
Version updated for https://github.com/soroush-tech/bench-action to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The bench-action GitHub Action automates benchmarking of TypeScript files using the @soroush.tech/bench package in a Docker sandbox. It fails the CI build if any case drops below a specified minimum speed ratio compared to the baseline case, and posts results as a sticky PR comment using the bench bot if configured with the id-token: write permission. The action is easy to use as it doesn’t require installation or setup beyond selecting a release tag.
July 24, 2026
Sigbound
Version updated for https://github.com/surya-koritala/sigbound to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound automates the process of merging code changes from multiple AI coding agents in parallel, resolving conflicts using a model and verifying merges before they land. It uses Git worktrees to handle each agent’s work independently and combines non-conflicting changes efficiently. The action is customizable with various commands for planning, running agents, resolving conflicts, verifying merges, and repairing failed builds, allowing users to harness their own AI models for effective collaboration.
July 24, 2026
RustScript Action
Version updated for https://github.com/VladasZ/rustscript to version v0.2.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows running Rust scripts without compiling them. It supports a practical subset of the language and provides features like rust check to validate scripts without executing them. The interpreter does not implement a second type system, but it handles errors and panics as expected for compiled Rust code.
July 24, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a scriptable, CI-friendly test harness that accurately reproduces Claude Cowork’s observable runtime contract. It supports various testing scenarios and environments, including local skills and live tiers with multi-node setups and Docker containers. The tool helps developers automate their skill testing across different platforms and ensures consistent behavior with real Cowork runs.
July 24, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v4.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a linter tool that validates configuration files and directories related to Claude, Cursor, Codex, and MCP agents. It checks for various rules such as plugin paths, hook paths, skill frontmatter, agent fields, prompt quality, and more. The action can be used via GitHub Actions or pre-commit hooks, with the option to run specific rules or suppress them based on a configuration file.
July 24, 2026
zizmor-action
Version updated for https://github.com/zizmorcore/zizmor-action to version v0.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action, zizmor-action, automates the execution of the zizmor security scanning tool in a GitHub workflow. It provides detailed analysis of code to identify potential vulnerabilities and helps developers triage issues more efficiently. The action supports both public and private repositories with various configurations like severity thresholds, token management, and output formats. Users can integrate it into their workflows for continuous security monitoring without relying on advanced security features.
July 23, 2026
slopscore-lint
Version updated for https://github.com/jman4162/slopscore to version v0.8.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary slopscore is a transparent linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify specific writing issues, encouraging clearer, more specific prose. The tool is designed as a prose linter rather than an AI detector for authorship, focusing on detecting common writing patterns that are characteristic of AI-generated or low-effort content.
July 23, 2026
Bulk GitHub Organization Settings Sync
Version updated for https://github.com/joshjohanning/bulk-github-org-settings-sync-action to version v1.13.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the bulk configuration of various GitHub organization settings across multiple organizations using a declarative YAML configuration file. Key features include syncing custom property definitions, values, rulesets, issue types and fields, member privileges, repository policies, and .github repository files. The action supports dry-run mode for previewing changes and provides per-organization overrides via YAML configuration. It also offers rich job summaries with per-organization status tables for easy tracking of changes. The action is designed to support GitHub.com, GHES, and GHEC platforms.
July 23, 2026
datamodel-code-generator
Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.70.0.
This action is used across all versions by 3,357 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating Python data models from various schema definitions, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It supports converting raw data (JSON/YAML/CSV) into Python model output types, retargeting existing Pydantic, dataclass, or TypedDict classes, and outputs models in different styles like Pydantic v2, Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with $ref, allOf, oneOf, anyOf, enums, and nested types, producing type-safe, validated code that is ready for IDEs and type checkers.
July 23, 2026
agent-test-verifier
Version updated for https://github.com/LaterKidsXD/agent-test-verifier to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-test-verifier (atv) is a static analysis tool that detects patterns commonly used by coding agents to bypass bug fixes and fool test suite verification. It scans diff files for changes that could lead to fake passing tests, such as force-pass hooks or assertion weakening. The tool can be used in CI pipelines to ensure that code changes actually fix bugs rather than just manipulate the test output.
July 23, 2026
jira-cve-action
Version updated for https://github.com/levigo/jira-cve-action to version v1.24.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action takes vulnerabilities from Trivy scans and creates Jira issues for each vulnerability. It automatically adds these issues as subtasks under a parent issue and can move them between states based on whether they have a fix version or not. The action also ensures that CVEs are shared across multiple projects in the same Jira instance, with project-specific versions marked on each issue.
July 23, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.12.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: lgtmaybe is a provider-agnostic GitHub Action that automatically reviews pull requests by analyzing the diff. It provides a comprehensive review including logic and correctness bugs, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent misalignment, and potential ponytail (code redundancy) issues. The tool uses OpenAI models to generate inline comments and a summary of the PR’s changes, handling sensitive information securely and efficiently.
July 23, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.104.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a tool that automates the process of creating and enforcing coding rules within repositories using Markdown lessons. It ensures that project-specific knowledge and lessons are stored alongside the code, preventing inconsistencies between sessions and reducing the need for constant re-explanations. By compiling lint rules from these lessons, Totem provides a deterministic, offline linter that helps maintain architectural integrity and velocity.
July 23, 2026
Setup iso8583tool
Version updated for https://github.com/nao1215/setup-iso8583tool to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the iso8583tool CLI, a tool for generating and parsing ISO 8583 messages, on your CI/CD pipelines. It downloads prebuilt binaries instead of building from source, ensuring fast execution times across Linux, macOS, and Windows platforms. The action allows you to specify a version to install and verify checksums or attestation.
July 23, 2026
LinkML (linkml-scala)
Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action linkml-scala-action automates the validation and generation of LinkML schemas using Node.js. It supports various commands like validate and generate, with options to specify schema files, strict mode, and output directories. The action can emit annotations to GitHub PRs, making it easier to track issues in schema definitions.
July 23, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor automates the auditing of AI agent configurations across repositories to ensure consistency and accuracy in instruction sets. It helps consolidate scattered guidance into a single AGENTS.md file, improves agent answers by consolidating conflicting instructions, and measures improvements in latency and cost. The tool also detects issues such as overlapping files, mismatched declarations, and conflicts within the same scope.
July 23, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.8.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the provisioning of a Postman workspace by generating baseline, smoke, and contract collections based on an OpenAPI specification. It includes dynamic contract tests that validate request/response schemas, security checks, and multi-protocol support. The action provides executable contract tests and logs the Postman CLI in for spec linting.
July 23, 2026
Postman Onboarding Insights Linking
Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of services discovered by Postman Insights to a Postman workspace and Git repository, ensuring they are linked with collections, repo links, and live telemetry. It requires human-user credentials and a specific region for the insights agent discovery mode. The action does not deploy the agent or perform other setup tasks but provides a link mechanism once the service is discovered.
July 23, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.13.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI, mocking servers, and monitors around them. It solves the problem of managing API assets (collections, environments, mocks, monitors) in a centralized location within a Git repository. Key capabilities include:
July 23, 2026
quantakrypto Quantum Readiness Scan
Version updated for https://github.com/quantakrypto/pqc-tools to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of identifying quantum-vulnerable cryptographic vulnerabilities in codebases using qScan, a CLI tool that scans various programming languages for RSA, (EC)DH, ECDSA, and EdDSA implementations. The action uploads SARIF formatted reports to GitHub Checks and fails the build if any new quantum-vulnerable crypto is found, providing an integrated solution for post-quantum readiness testing in CI environments.
July 23, 2026
UnityPackage Builder
Version updated for https://github.com/r74tech/create-unitypackage to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of Unity .unitypackage files by downloading a precompiled native CLI, verifying its integrity, and executing it to package assets. It simplifies the process of bundling Unity projects into portable formats across different platforms. The action supports Linux, macOS, and Windows, with options for customizing the project directory, asset files, and output path.
July 23, 2026
Redis Repo Memory
Version updated for https://github.com/redis-learn/redis-repo-memory to version v1.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Redis Repo Memory is a GitHub Action that automates the process of finding semantically related pull requests, issues, and commits from repository history. By using OpenAI’s text-embedding-3-small API to embed the context of each commit or PR, it searches a Redis vector index for similar prior work and posts the results as a comment on pull requests and a status update in push events. The action helps teams stay informed about what has been done before by providing insights into related content across their repository history.
July 23, 2026
Project Health Score
Version updated for https://github.com/RohitS456/project-health-score to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of assessing project health by scanning for common best-practice files and calculating a health score. It identifies various checks such as existence of README, LICENSE, tests, CONTRIBUTING guide, code of conduct, GitHub Actions configuration, security policy, and Dependabot setup. The tool posts the results as a PR comment and job summary, allowing users to monitor and improve project health.
July 23, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.41.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter written in Rust that provides over 76 lint rules to ensure consistency and best practices in Markdown files. It offers built-in formatting capabilities, automatic fixes, multi-flavor support, and zero dependencies. With its focus on speed and user experience, rumdl is suitable for both developers and CI/CD pipelines, making it a versatile tool for Markdown quality assurance.
July 23, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.58.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines. It automates the detection of misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various 13 agent platforms. Unlike hosted scanners that rely on LLMs for judgment, AgentAuditKit runs fully offline and deterministically, ensuring that findings are consistent across re-runs and audits. It also produces auditor-ready compliance-evidence packs in SARIF format along with PDF reports mapped to 13 security frameworks.
July 23, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.25.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is a GitHub Action that automates code review by running multiple specialized AI reviewers in parallel and using an evidence-based curator to verify findings before posting review comments on pull requests. It optimizes for recall instead of precision, ensuring more real bugs are caught while minimizing false positives. The action supports various LLMs and provides markdown-based custom lenses for tailored reviews.
July 23, 2026
Socket Basics Security Scanner
Version updated for https://github.com/SocketDev/socket-basics to version v2.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 8 repositories.
Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Socket Basics automates comprehensive security scanning using SAST, secrets detection, container scanning, and more. It normalizes outputs into Socket’s standardized format and delivers consolidated results through notification channels. Users can configure policies in the Socket Dashboard, eliminating the need for GitHub Actions workflow changes. The action supports zero configuration, unified scanning across various technologies, PR comments, centralized management, and a comprehensive guide on installation methods.
July 23, 2026
RustScript Action
Version updated for https://github.com/VladasZ/rustscript to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a RustScript interpreter that automates the process of running and validating Rust scripts without the need to compile them fully. It supports executing and checking Rust code directly from files or snippets, providing a practical way to prototype and test small scripts without waiting for full compilation times.
July 23, 2026
AI-Driven ADR Enforcer
Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.7.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI-Driven ADR Enforcer automates the auditing of incoming Pull Requests against Architecture Decision Records (ADRs) by leveraging LLMs to ensure architectural compliance. It dynamically reads local ADR files, evaluates code diffs in real-time, and provides inline suggestions for fixing architectural violations, thus preventing drift and technical debt accumulation. The Action offers self-healing features, automated quality gates, and a safety risk assessment pipeline for small changes.
July 23, 2026
Capture Environment Variable Checker
Version updated for https://github.com/YhaliWaizman/Capture to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static analysis tool that identifies discrepancies between environment variables declared in .env files and their usage in various programming languages, Dockerfiles, and Docker Compose files. It helps detect potential security risks by identifying hardcoded secrets and cross-checks variables across different sources to ensure consistency. The action supports parallel scanning and incremental caching for efficient performance.
July 23, 2026
Pi Code Assist
Version updated for https://github.com/zeldrisho/pi-code-assist to version v2.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action runs the Pi coding agent as a small, composable tool, executing one non-interactive prompt and streaming the response to the job log while exposing it to later steps. It allows users to specify a prompt, API key, provider, model, and optional parameters like thinking level and tools.
July 23, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a Rust-based linter designed to validate various configuration files used by Claude Code, Cursor, Codex, and standalone MCP. It provides lint rules, two modes (Basic and Plugin), configurable suppression or downgrade of rules, focused execution, GitHub Action integration, cross-platform binaries, and CLI options for linting and diagnosing issues in agent configurations.
July 23, 2026
Validate Syscribe Model
Version updated for https://github.com/sjames/syscribe to version v0.32.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe is a tool that converts SysMLv2 models into human-readable Markdown files with YAML frontmatter, making them version-controlled and traceable. It automates the process of generating requirements, test cases, architecture decision records, and safety analysis reports from natural language descriptions using large language models (LLMs). The action supports various element types and provides features for cross-repository composition, security analysis, and IEC 62443 zones & conduits.
July 23, 2026
Muninn Security Scanner
Version updated for https://github.com/skaldlab/muninn to version v0.3.6.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanning tool designed to integrate with GitHub Actions workflows. It automates the process of identifying vulnerabilities across various tools, normalizes their output, and presents findings in a unified format as comments on pull requests, SARIF uploads, and structured JSON. Muninn uses eight popular vulnerability scanners to detect secrets, pipeline misconfigurations, syntax errors, supply chain risks, application SAST issues, dependency vulnerabilities, container image vulnerabilities, and infrastructure-as-code misconfigurations, providing a comprehensive security scan of GitHub Actions pipelines and self-hosted CI environments.
July 23, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, supporting various themes, template engines, SEO features, and deployment options. It automates the process of generating clean URLs, feeds, search indexes, and more, making it suitable for building blogs, documentation sites, and landing pages efficiently.
July 23, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The spek GitHub Action provides a lightweight, read-only viewer for OpenSpec content, offering structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It automates the process of displaying and managing specs, changes, and tasks in a single interface, making it easier to collaborate and understand complex projects.
July 23, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.60.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub App Token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting the Nix configuration from a Flake. It also supports caching with niks3 for better performance on self-hosted runners. The action is designed to run efficiently (< 1 minute) and can be used with various runner types (GitHub Actions, Gitea, Forgejo).
July 23, 2026
Sprocket CI/CD
Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.28.0.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static analysis of WDL documents using Sprocket, a tool for validating and linting WDL files. It provides subcommands for check, lint, and validate, allowing users to enforce coding standards and detect potential issues in their workflows. The action can be configured with input parameters such as lint rules, ignore patterns, and deny options. It also supports formatting checks using a sprocket.toml configuration file.
July 23, 2026
xilo-nix-cache
Version updated for https://github.com/stubbedev/xilo to version v1.0.10.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The xilo action is a self-hosted Nix binary cache written in Go. It offers single-tenant multi-user support, content-addressed chunk deduplication, and supports local or S3 storage backends. Key features include instant token revocation, no stalls on concurrent pushes, a cachix-style admin dashboard, and a 9 MB Docker image serving zstd pulls directly from stored frames.
July 23, 2026
Sudden Agent
Version updated for https://github.com/sudden-network/agent to version v1.14.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sudden Agent automates tasks on GitHub workflows through programmable agents. It solves problems related to automating code reviews, issue triage, security audits, and version management by providing customizable prompts and session persistence across different actions in the workflow. The action supports various models and authentication methods for different agents.
July 23, 2026
Sigbound
Version updated for https://github.com/surya-koritala/sigbound to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound automates the process of running multiple AI coding agents on one repository in parallel, merging their work automatically. It handles conflicts by using a model to resolve them and ensures that only changes that build and pass your tests are landed. The action is designed to be flexible, allowing users to bring their own model for planning, agent execution, conflict resolution, and merge repair.
July 23, 2026
Folder Hash v2
Version updated for https://github.com/tankist/folder-hash to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates the hash of specified folders and outputs the result, which can be used to generate cache keys or as a checksum for folder content. It supports caching multiple folders and uses glob patterns for file selection.
July 23, 2026
Tenzai Test
Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates AI-powered security testing of deployments directly from CI pipelines. It sends a commit-diff test against an existing Tenzai application and provides real-time feedback on vulnerabilities, automatically triggering a Tenzai Test check run in the tested commit. The action requires a production Tenzai service-account access key and app ID, validates configuration, and supports dry runs for testing purposes.
July 23, 2026
Soundcheck Security Review
Version updated for https://github.com/thejefflarson/soundcheck-action to version v1.0.39.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Soundcheck Security Review (v2) GitHub Action automates the execution of Soundcheck, an OWASP-focused static code analysis tool. It performs a security review on all changes in a pull request or a scheduled scan across the repository, providing a severity-ranked findings table and optional autofix capabilities that rewrite critical issues directly into the affected files.
July 23, 2026
Translatize Sync
Version updated for https://github.com/Translatize/sync-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Translatize Sync is a GitHub Action that automates the synchronization of source keys and translations between a local repository and a Translatize project. It simplifies the process by providing commands to push new source keys, pull completed translations, and gate pull requests based on missing or changed strings. The action uses a branch-bound API token for authentication and supports configuration via translatize.config.json.
July 23, 2026
repo-trust-scan
Version updated for https://github.com/Uky0Yang/repo-trust-scan to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary repo-trust-scan is a CLI and GitHub Action that statically scans repository-controlled execution surfaces, helping users identify and understand potential security risks before executing unfamiliar code. It checks tasks like automatic editor actions, agent hooks, MCP server configurations, devcontainer lifecycle commands, package install hooks, escaping symlinks, hidden Unicode in instructions, download-and-execute chains, and credential-transfer patterns. The action is useful for ensuring that repositories are secure and safe to work with, complementing existing security tools but not replacing them.
July 23, 2026
urldn-link-check
Version updated for https://github.com/URLdn/link-check to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans Markdown and MDX files to find broken, redirected, insecure HTTP links, and excessively long URLs. It can be used as a CLI or as part of a continuous integration pipeline to ensure the integrity of documentation links.
July 23, 2026
difftrace
Version updated for https://github.com/vanandrew/difftrace to version v1.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action difftrace automates change detection in monorepos by analyzing the uv.lock file to build a dependency graph, mapping changes to packages, and identifying transitively affected packages. It identifies which packages are directly or indirectly impacted by code changes, optimizing CI pipelines to only process relevant packages.
July 23, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.722.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action provides a comprehensive local codebase intelligence tool for AI coding agents. It automates several key tasks including generating a deterministic code graph, calculating drift scores to measure how far behind the codebase is in terms of runtime dependencies and library versions, and providing ranked upgrade priorities for maintaining up-to-date dependencies. The action runs entirely on your machine, ensuring no network calls or data leaves your repository unless explicitly pushed.
July 23, 2026
Repo Settings as Code
Version updated for https://github.com/Vivswan/repo-settings-as-code to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Repo Settings as Code GitHub Action automates the application of declarative repository settings from a .github/settings.yml file to GitHub repositories. It provides a loud, stateless replacement for the Probot Settings app, which also handles rulesets (branch, tag, and push). The action ensures that every apply is visible and fails with API error messages, ensuring no silent failures occur. It supports setting up fine-grained Personal Access Tokens (PATs) as repository secrets, using them to manage permissions and settings declaratively in YAML format.
July 23, 2026
RustScript Action
Version updated for https://github.com/VladasZ/rustscript to version v0.1.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Rust script execution by interpreting a practical subset of the language without compiling the entire project. It supports running scripts directly as binaries or executing snippets in compiled form, validating without running, and providing a list of supported methods per receiver and engine. The action is particularly useful for small scripts that do not require compilation to run efficiently.
July 23, 2026
Hurd-vm
Version updated for https://github.com/vmactions/hurd-vm to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/hurd-vm allows users to run CI tests in the Hurd operating system. It automates the setup and execution of CI scripts on Hurd, a Unix-like operating system derived from GNU/Hurd. This action provides features such as sharing code between the host and VM, using different synchronization methods like rsync, nfs, or scp, and NATting ports to allow for remote access to the VM.
July 23, 2026
Void Checkout
Version updated for https://github.com/void-musl/checkout to version v1.0.0-treeless.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action checkout checks out a repository in treeless mode, which includes only the files and directories specified in .gitattributes. This is useful for creating lightweight clones of repositories that do not include unnecessary binary or large files. The action automates the checkout process by using the default ref (github.ref) if not provided, and supports specifying the repository name and server URL as inputs.
July 23, 2026
Void Upload
Version updated for https://github.com/void-musl/upload-release to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading files to a specific release on GitHub. It simplifies the task by requiring only essential inputs such as the tag, release name, file pattern, and GitHub token. The main functionality is to allow developers to easily publish build artifacts or binary files directly from their workflows.
July 23, 2026
wartzar-bee CI Cost Guardrail
Version updated for https://github.com/wartzar-bee/ci-guardrail to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action wartzar-bee/ci-guardrail calculates the cost difference between the base and head branches of a PR, posts a comment with the delta and top contributors, and can block the build if the token cost increases beyond a configured threshold. It uses @wartzar-bee/tokenscope to estimate token costs based on file size and complexity, providing insights into potential cost regressions.
July 23, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates a headless, scriptable, CI-ready test harness for testing Claude Cowork skills. It reproduces Claude Cowork’s observable runtime contract closely enough to test the skills you write across multiple scenarios and in CI environments, without using the locked Desktop app. The action supports various fidelity tiers including replay, lint, container, hostloop, and microvm, each requiring different prerequisites such as a running agent, a Claude token, and a Docker or Lima runtime.
July 23, 2026
AGENTS.md Lint (Schliff)
Version updated for https://github.com/Zandereins/schliff to version v8.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files using the Schliff tool. It ensures that AI instruction files remain consistent across different systems by providing deterministic quality scores based on a versioned rubric. The action helps detect and prevent issues in instruction files that could degrade LLMs, ensuring better reliability in AI development workflows.
July 23, 2026
Sparda Security Gate
Version updated for https://github.com/zyx77550/sparda to version v0.67.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles and statically verifies the behavior of AI-written backend services to ensure their correctness before deployment. It provides deterministic proof that routes, guards, invariant checks, and transaction boundaries do not break, without requiring API keys or cloud accounts. The action automates the process of proving the safety of AI-written backends locally and can generate proofs, badges, and coverage reports.
July 22, 2026
FHIR Validator
Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a TypeScript-based FHIR validator designed to automate validation of FHIR JSON resources in CI pipelines, GitHub Actions, or standalone Node.js environments. It supports multiple FHIR versions (R4, R4B, R5, R6) and provides features such as validating against StructureDefinitions, FHIRPath expressions, terminology bindings, references, slicing, extensions, Bundle rules, metadata, and custom rules without requiring a JVM or database. The action is available for both GitHub Actions pinning using floating tags and exact version pins, ensuring reproducibility and auditability.
July 22, 2026
attest-vm-image
Version updated for https://github.com/meigma/attest-vm-image to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The attest-vm-image GitHub Action inspects a finished QCOW2 VM disk image to produce auditable evidence about its contents and optionally signs that evidence. It helps verify the integrity of an artifact, ensures compliance with security policies, and provides detailed reports on vulnerabilities and contamination during the build process. The action is designed to be run after an image has been built and does not modify the input image.
July 22, 2026
Microsoft Store App Publisher
Version updated for https://github.com/microsoft/microsoft-store-apppublisher to version v1.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 53 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
July 22, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.97.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scanning and discovery of security vulnerabilities in AI, MCP, and cloud infrastructure. It can scan from CLI, CI, Docker, or a self-hosted control plane via cloud connect or scheduled estate scans. The action generates centralized evidence and enforces runtime MCP/tool calls.
July 22, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.29.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating a proxy cache with new Go module releases based on tag creations. It supports both standard and submodule version tags and can be configured to use custom proxies or import paths, allowing users to integrate it into their workflows for continuous integration of Go modules.
July 22, 2026
Shoutrrr GitHub Notifications Action
Version updated for https://github.com/nicholas-fedor/shoutrrr-action to version v1.0.21.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending notifications using Shoutrrr from your GitHub Actions workflows. It allows you to easily integrate service notifications like Slack, Discord, or Telegram into your CI/CD pipelines without manually handling them. The action supports custom URLs for various services and provides an optional title parameter to customize notifications.
July 22, 2026
Cerberus AI-Agent Runtime Check
Version updated for https://github.com/Odingard/cerberus-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cerberus’s allow/block behavior by running two bundled, maintained fixtures through the Cerberus runtime security layer. It provides a PASS/FLAG/BLOCK verdict and an uploaded evidence artifact, ensuring CI runs without disruptions. The action is report-only by default but can be configured to fail if protection does not behave as expected.
July 22, 2026
MergeRisk
Version updated for https://github.com/One-Code-LLC/mergerisk-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MergeRisk is a GitHub Action that provides a concise pull-request merge-risk report based on both deterministic scoring and optional AI insights. It helps developers identify potential risks associated with pull requests, especially those involving critical and medium path changes, without relying solely on AI. The action can be configured to fail the build if a certain risk level is reached, making it useful for maintaining code quality and security.
July 22, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding action automates the setup and execution of a comprehensive suite of tasks to onboard an API repository, including workspace creation, OpenAPI upload, collection generation, repository artifact sync, and test execution. It provides a single entry point for handling the onboarding path, ensuring executable, standards-grounded tests are left behind in addition to assets.
July 22, 2026
Postman Onboarding AWS Spec Discovery
Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v3.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using your existing credentials. It handles AWS region setup, automatically detects providers based on IAM permissions, and resolves specs before calling AWS. The action is part of a suite to streamline Postman onboarding processes for AWS services, allowing users to integrate with their Postman environments efficiently without the need for additional GitHub tokens.
July 22, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections that include executable test cases based on the spec, covering various protocols and standards like RFCs, gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of a larger suite for automating API testing and onboarding in Postman.
July 22, 2026
Postman Onboarding Insights Linking
Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of services discovered by the Postman Insights DaemonSet agent to a Postman workspace and git repository. It solves the problem of automatically associating new insights with existing workspaces, environments, and service accounts after deployment. The action provides capabilities to link a discovered service to a workspace, environment, and retrieve credentials for post-processing steps like acknowledging the discovery and binding applications.
July 22, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.10.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Postman Onboarding: Repo Sync automates the process of exporting Postman collections and environments into a repository. It also sets up CI, mock servers, and monitors around these assets. The action requires a Postman API key or service-token to generate tokens and workspace IDs from inputs or .postman/resources.yaml. The example usage shows how to set up a full sync with workspace assets using the action.
July 22, 2026
Postman Onboarding Service Token
Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of minting a fresh service-account access token and team ID for use in Postman API Onboarding workflows. It ensures that the credentials are up-to-date and ready to be used by downstream actions, handling both quick start and scheduled repo-secret refresh scenarios based on the specified region.
July 22, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action reshapes a Postman Smoke collection to match a curated flow.yaml file. It automates the process of integrating smoke tests into a project’s API onboarding workflow, providing optional runtime authentication injection for OAuth2 and API keys through the Postman gateway. The action is part of the Postman API Onboarding suite and requires credentials such as the Postman API key and access token to perform its operations.
July 22, 2026
Rafter Security Scan
Version updated for https://github.com/Raftersecurity/rafter-cli to version v0.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of scanning codebases using the Rafter security tool. It helps identify potential security vulnerabilities and ensures that code is compliant with security standards. The action supports various programming languages and can be integrated into CI/CD pipelines to enhance the overall security posture of applications.
July 22, 2026
Agent-Safe Commit Guardrails
Version updated for https://github.com/ravisingh11/agent-safe-engineering to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent-Safe Engineering is an automated tool designed to ensure AI-generated code changes are understandable and maintainable by humans. It uses human-readable standards, configurable guardrails, focused agent skills, and deterministic validators to enforce constraints on automated code modifications. This ensures that the changes are not only safe but also auditable and reversible.
July 22, 2026
AIBOM Scanner
Version updated for https://github.com/saasvista/aibom-scanner to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action scans codebases for AI SDK usage and generates an AI Bill of Materials (AIBOM) with compliance risk findings mapped to NIST AI RMF, ISO 42001, and EU AI Act. It detects AI SDKs in various programming languages, including Python, JS/TS, Go, Java, Rust, Ruby, Swift, C#,/.NET, and provides comprehensive coverage accounting and zero dependencies.
July 22, 2026
Reelier replay
Version updated for https://github.com/seldonframe/reelier to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Reelier is an open-source tool designed to help agents record and reproduce their work deterministically, ensuring that every run produces identical results. It automates the process of creating a “skill” file from an agent’s existing session, capturing all steps in a receipt that can be replayed without any LLM or tokens, and diffing it against previous versions to catch drift. This helps ensure that long-run operators can verify the reliability and reproducibility of their agent workflows without relying solely on manual verification.
July 22, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.21.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI-driven code review tool that leverages multiple specialized AI reviewers to identify potential issues in a pull request. It uses an evidence-based curator to verify findings and only dismisses them if they can be substantiated with code from the diff, ensuring high recall and manageable false positives. The tool supports various LLM providers and allows for customization through Markdown-based lenses.
July 22, 2026
Huawei AppGallery Connect Publish
Version updated for https://github.com/Siyabulela/huawei-appgallery-publish-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Huawei AppGallery Connect Publish Action uploads an app package (APK, AAB, or RPK) to Huawei AppGallery Connect via the official Publish API, automatically updating file info and leaving final submission as a manual step in the AGC console. This action is designed to replace unmaintained community actions and uses direct Huawei Publish API calls without third-party dependencies. It requires setting up an API client with specific permissions and scopes to avoid common pitfalls.
July 22, 2026
Graceful Boundaries Conformance Check
Version updated for https://github.com/snapsynapse/graceful-boundaries to version v1.5.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graceful Boundaries is a specification for how services communicate their operational limits to humans and autonomous agents. It addresses three gaps in existing standards, providing proactive discovery of limits before they are hit, structured refusal with explanatory details and next steps, and constructive guidance. The specification applies to every HTTP error class, not just rate limits.
July 22, 2026
Skill Provenance Validate
Version updated for https://github.com/snapsynapse/skill-provenance to version v6.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Skill Provenance is a GitHub Action that ensures the integrity and version control of Agent Skills. It helps teams manage and verify the version, staleness, and drift of their skills across different platforms and sessions. By embedding version information and hash-based integrity checks within the skill bundle, Skill Provenance allows for portable provenance and trust verification.
July 22, 2026
PlatformIO Dependency Updater
Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-b2.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PlatformIO Dependency Updater is a GitHub Action that checks for dependency updates in the platformio.ini file and creates pull requests when newer versions are available. It supports various dependency sources, including PlatformIO Registry, GitHub, GitLab, Bitbucket, and Arduino libraries, and can handle pre-release versions and custom package versions. The action automates dependency management by creating dedicated update branches, updating dependencies, and opening pull requests, while also maintaining the number of open dependency PRs to 5 and applying labels if they exist. It includes a 3-day cooldown for new releases to avoid faulty versions and manages updates for inactive repositories after 3 months.
July 22, 2026
RustScript Action
Version updated for https://github.com/VladasZ/rustscript to version v0.1.6.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets and executes Rust scripts without compiling them, offering features like running scripts directly, validating code with rust check, caching compiled binaries with rust build, and managing builds with rust clean. It supports a subset of the Rust language and provides tools for interacting with files and system commands.
July 21, 2026
setup-openapi
Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.11.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-openapi GitHub Action installs and caches the OpenAPI Generator CLI, which allows users to generate API client libraries from OpenAPI specifications. It provides a simple way to automate the generation of clients for various programming languages within GitHub Actions workflows. The action supports specifying the version and binary name of the generator tool, making it flexible for different use cases.
July 21, 2026
codemetrics complexity gate
Version updated for https://github.com/richardwooding/codemetrics to version v0.12.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action codemetrics automates the calculation of cyclomatic and cognitive complexities for functions across various programming languages. It provides a comprehensive solution for checking pull request complexity, helping developers maintain code quality by ensuring that new or modified functions do not exceed predefined thresholds. The action is designed to be efficient, using one pass analysis with support for multiple languages through Tree-sitter integration.
July 21, 2026
file-search-on review gate
Version updated for https://github.com/richardwooding/file-search-on to version v0.119.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: The file-search-on GitHub Action helps in searching and filtering files based on metadata attributes using a CEL expression. It supports multiple file formats across various content type families, including documents, data, images, audio, video, office, ebooks, plain text, archives, compiled binaries, email, and source code.
July 21, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.38.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust that offers speed, numerous lint rules, automatic formatting with –fix, zero dependencies, configurable TOML-based settings, support for multiple Markdown flavors, installation options via Cargo, npm, pip, uv, mise, Nix, Termux User Repository, pacman, and binary downloads. It compares well to markdownlint and provides modern CLI tools with detailed error reporting and CI/CD integration.
July 21, 2026
SchemaCrawler (Local) Action for GitHub Actions
Version updated for https://github.com/schemacrawler/SchemaCrawler-Local-Action to version v17.12.2.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of a SchemaCrawler report for database connections using local installations on Linux-based runners. It solves the need for continuous database schema inspection and compliance checks within GitHub workflows, providing detailed reports for database administrators or developers.
July 21, 2026
BoundaryCI tenant-isolation scan
Version updated for https://github.com/sir-gig/boundaryci to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local-first CLI tool designed to scan Supabase and PostgreSQL projects for cross-tenant authorization issues before migrations are applied to production. It reconstructs the final security state from SQL migrations, applies deterministic tenant-isolation rules, and optionally adds managed or bring-your-own-key Fireworks review for policy interactions that static rules cannot reliably understand. The tool is particularly useful for identifying exposed schema restrictions and ensuring that RLS policies are correctly configured across multiple tenants.
July 21, 2026
Agent Gate for AI PRs
Version updated for https://github.com/sjh9714/mergewarden to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MergeWarden is an AI PR review tool that checks GitHub pull requests against predefined boundaries and policies to ensure they do not interfere with the agent control plane or introduce unauthorized text into agentic workflows. It helps maintain the integrity of repositories by detecting potential security risks and ensuring compliance with defined scopes. MergeWarden does not execute code, load policy from the PR head, or call an LLM at runtime, providing deterministic evidence for each decision.
July 21, 2026
GuardLayer Scan
Version updated for https://github.com/solvionsolutions/guardlayer-scan to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardLayer Scan is an open-source GitHub Action that provides security scanning for Next.js + Supabase applications by automating static analysis to identify and comment on potential vulnerabilities, such as exposed secrets, missing Row Level Security, unverified webhooks, and unguarded Server Actions. The action runs in your CI pipeline without requiring signup or account creation, providing inline annotations on pull requests before they are merged.
July 21, 2026
Environment/Output Setter
Version updated for https://github.com/somaz94/env-output-setter to version v1.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Environment/Output Setter is a versatile action that enables users to dynamically set environment variables and outputs within their workflows. It supports setting multiple key-value pairs in both $GITHUB_ENV and $GITHUB_OUTPUT, making it ideal for automating tasks that require defining variables across different stages of the workflow. The action provides features like value transformation, masking sensitive values, JSON support, and retry mechanisms, enhancing its utility for complex environments.
July 21, 2026
Go Changelog Generator
Version updated for https://github.com/somaz94/go-changelog-action to version v1.0.10.
This action is used across all versions by 10 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a changelog from Conventional Commits in a Go project. It automates the process of creating detailed, structured change logs that include features, bug fixes, optimizations, and breaking changes. The action supports filtering by version tags, customizing section names, and includes options for dry runs and excluding certain authors or types of commits.
July 21, 2026
Go Git Commit Action
Version updated for https://github.com/somaz94/go-git-commit-action to version v1.8.0.
This action is used across all versions by 18 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Git commit, push, tag, and pull request operations using Go. It is designed to be fast, reliable, and secure, with features such as flexible file pattern support and built-in authentication handling. The action can create tags, push changes to a specified branch, and automatically create pull requests.
July 21, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building, deploying, and serving websites efficiently, making it suitable for blogs, documentation, and other content-driven projects. SSG supports various features like built-in themes, template engines, and deployment options to help users quickly create and deploy static sites.
July 21, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: spek is a lightweight, read-only viewer for OpenSpec content that provides a structured browsing interface with features such as BDD syntax highlighting, task progress tracking, and full-text search. It allows users to view specs, changes, and tasks in one place, aggregating worktrees of a repository into a single view for better visibility.
July 21, 2026
Node Semantic Release
Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.202.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The node-semantic-release GitHub Action automates Node.js project releases by installing dependencies, building the project, running semantic-release to determine and generate release notes, and optionally committing assets and creating a git tag or publishing a GitHub Release. The action supports two modes: release and publish, with options for using secrets.GITHUB_TOKEN or a Personal Access Token (PAT) for triggering downstream workflows.
July 21, 2026
Normalize Major Version Tag
Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.1.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action normalizes major version tags when a semantic versioning tag is pushed, ensuring that developers can consistently reference stable versions of the action. It works well with GitHub Actions versioning and supports dry runs to avoid unintended changes. To include the action in another repository, use the uses syntax with a branch or tag reference.
July 21, 2026
Repository Create
Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.83.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The repository-create action is a Node.js CLI that uses Octokit.js to dynamically create GitHub organization repositories and apply predefined general settings and branch rulesets. It supports both blank creation and template-based repository generation, with options for specifying visibility and writing job summaries. The action requires a GitHub Personal Access Token with specific scopes and can be used as an action in other workflows.
July 21, 2026
SunsetPR AI Model Lifecycle Check
Version updated for https://github.com/synergia-yoshi/sunsetpr-action to version v0.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SunsetPR AI Model Lifecycle Check action automatically detects deprecated OpenAI, Anthropic, and Google Gemini model IDs and API surfaces in CI before their shutdown date. It reports the exact file and line, shutdown date, official replacement or migration path, confidence, and provider-owned documentation. The action is user-friendly and provides a structured table to the GitHub Actions Job Summary with a machine-readable report written to .sunsetpr/report.json.
July 21, 2026
ArchGuard - Architectural Drift Detector
Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a tool that uses LLMs to detect architectural drift in code changes by comparing them against established Architectural Decision Records (ADRs). It helps prevent “architectural drift” by ensuring code adheres to the rules defined in ADRs. ArchGuard supports local analysis without sending sensitive data over the internet and can be configured via a YAML file for detailed settings.
July 21, 2026
Expand AWS IAM Wildcards
Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.4.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically expands IAM wildcard actions in PR diffs and posts inline comments showing what each wildcard matches, with links to AWS docs. It helps reviewers understand security posture changes more easily by providing inline comments with expanded actions linked to AWS documentation. The recommended setup includes a pull_request workflow trigger with write permissions for pull-requests and uses a full 40-character commit SHA for immutable reference.
July 21, 2026
gmetrics-action
Version updated for https://github.com/twangodev/gmetrics to version v1.7.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action gmetrics is a Go port of lowlighter/metrics, designed for generating SVG output paths using the metrics tool. It automates tasks related to performance monitoring and analysis by providing an alternative to the original metrics package. The action supports caching per-repo language stats across runs, optimizing processing for new commits.
July 21, 2026
Medicare NPI Revalidation Lookup
Version updated for https://github.com/unitedideas/medicare-revalidation-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Medicare revalidation checks action in GitHub Actions automates the process of validating public enrollment evidence and revalidation due dates for a list of NPIs against the CMS Medicare Revalidation List. It supports both demo and real rosters, with options to set hard charge caps. For larger datasets, it uses Apify to handle the lookup operations and can be used as an email reminder service or scheduled comparison tool. The action provides a free two-NPI demo without a token but requires an API token for real use cases.
July 21, 2026
MCP Test Harness
Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCP Test Harness is a CI gate for MCP servers, ensuring that AI agents’ connectors work correctly before deployment. It automates deterministic tests using pytest-style syntax, providing JUnit/SARIF reports and conformance badges to audit and govern the server’s functionality. The action supports multiple transports (stdio, SSE, HTTP) and integrates seamlessly with GitHub Actions, JUnit consumers, and Code Scanning for comprehensive testing coverage and security checks.
July 21, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.721.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action provides a local tool to analyze codebases, assess drift scores, and generate drift breakdowns. It automates tasks such as generating code graphs, calculating drift scores, and identifying upgrade priorities. The main purpose is to help AI coding agents understand the current state of a project’s dependencies, runtime lag, and EOL proximity on the developer’s machine without relying on external APIs or data transfer.
July 21, 2026
Gemini PR Reviewer
Version updated for https://github.com/vivek180905/Gemini-AI-PR-Reviewer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Gemini PR Reviewer automates code reviews for GitHub Pull Requests by leveraging Google’s Gemini AI to analyze git diffs, identifying bugs, performance issues, and security vulnerabilities. It posts actionable feedback directly on PRs, enhancing collaboration and maintaining high-quality code standards.
July 21, 2026
AGENTS.md Lint (Schliff)
Version updated for https://github.com/Zandereins/schliff to version v8.6.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files to ensure consistent quality across different environments. It uses a deterministic rule engine to evaluate instruction files against explicit rubrics, preventing degradation due to inconsistencies or rotting prompts. The action ensures that AI tools are consistently evaluated and can be trusted for their accuracy and reliability.
July 21, 2026
Pi Code Assist
Version updated for https://github.com/zeldrisho/pi-code-assist to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action installs the Pi coding agent, a small and composable tool that runs non-interactive prompts using pre-configured models and tools. It automates code reviews by providing actionable feedback on correctness, security, and test issues, while restricting permissions to read-only actions and untrusted project settings.
July 20, 2026
RoleCraft Action
Version updated for https://github.com/rolecraft-sh/rolecraft-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rolecraft-action automates the installation and verification of AI agent skills in a CI environment using the RoleCraft tool. It simplifies the process of ensuring that AI agents have all necessary skills for testing or deployment, by running specific commands to check skill integrity, install new skills, perform system health checks, and more.
July 20, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates CLI coding agents deterministically using plain Python, ensuring reproducibility of tasks across runs. It maintains a lineage spine to track every artifact write and replay journal to preserve the execution history. The tool supports various providers like Claude Code, Codex, Gemini CLI, and more, with features for auditing and verifying run results offline.
July 20, 2026
Muninn Security Scanner
Version updated for https://github.com/skaldlab/muninn to version v0.3.5.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanner that integrates multiple best-in-class tools into a single workflow, automating security checks and reporting unified findings as GitHub PR comments, SARIF uploads, and structured JSON. It normalizes scanner outputs, collapses duplicate findings across different scanners, and provides attribution for each scan, improving visibility and reliability in CI/CD pipelines.
July 20, 2026
Cloudflare API Shield Upload
Version updated for https://github.com/SocksTheWolf/cloudflare-upload-spec to version v1.1.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading OpenAPI specifications to Cloudflare API Shield. It allows users to upload their specifications without manual intervention, which can save time and improve efficiency. The action provides parameters for specifying the zone ID, file name, and other options to customize the upload process. By using this action in a CI/CD pipeline, developers can ensure that their API specifications are up-to-date and available on Cloudflare’s platform automatically.
July 20, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code review tool that uses AI to analyze and generate structured comments in repositories. It automates the process of reviewing pull requests, issues, and comments, providing insights into potential security vulnerabilities, dependencies risks, and other issues. By keeping the review logic in the repository, Pipr ensures consistency and traceability of reviews across different code hosts. The tool supports integration with GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud, using provider adapters to maintain a neutral configuration format.
July 20, 2026
stackql-exec
Version updated for https://github.com/stackql/stackql-exec to version v2.4.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 11 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of stackql queries within a GitHub workflow. It supports various authentication methods and provides options for querying, data processing, and output format customization. Key features include handling inline queries, query files with external variables, and support for JSON/JSONnet data preprocessing. The action simplifies integration of stackql operations into CI/CD pipelines, making it easier to manage cloud resource configurations and validations.
July 20, 2026
Tenzai Test
Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates the process of triggering an AI-powered security test on a deployed application after a successful CI/CD pipeline. It checks if the deployment is a valid step in the workflow and initiates a commit-diff test against an existing Tenzai application. The action provides real-time feedback through the Tenzai GitHub App, which posts a check run with the results of the security scan upon completion.
July 20, 2026
Keep Node Current
Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes Node.js versions used across the repository with the official Node.js release schedule, updating CI matrices, single-version pins, .nvmrc, and package.json files. It automatically detects and removes end-of-life major versions and adds new ones when necessary, ensuring all declared versions are compatible with the current schedule. The action creates separate commits for each change (drop or add) and updates the PR title accordingly.
July 20, 2026
grype_me
Version updated for https://github.com/TomTonic/grype_me to version v1.3.18-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of project dependencies and vulnerabilities using the latest Grype database. It provides a simple interface to scan repositories, container images, directories, or SBOMs, generating detailed reports and badges that can be used in READMEs. The action is designed to be lightweight and fast, leveraging pre-downloaded databases to speed up vulnerability scans compared to installing Grype during each run.
July 20, 2026
GSC Indexer
Version updated for https://github.com/toolsura/gsc-indexer to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action toolsura/gsc-indexer re-indexes URLs via the Google Search Console URL Inspection API. It automates the process of pushing blog pages into or refreshing them in the index when at least “site full user” rights are held on the property. The action can handle single URLs, batch files, and sitemaps, providing a way to track indexed vs not over time with -report/-diff. It is also published as a GitHub Action, enabling CI re-indexing of blog content directly from pushes to the repository.
July 20, 2026
AWS CDK Diff PR Commenter
Version updated for https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter to version v1.5.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 6 repositories.
Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically posts the output of cdk diff as a comment on Pull Requests, helping teams review infrastructure changes directly within their PR workflow. It updates existing comments and supports custom headers for better organization in multi-stack setups, parsing and highlighting IAM statement changes, Security Group changes, Parameters, and Resources.
July 20, 2026
Terraform Plan PR Commenter
Version updated for https://github.com/towardsthecloud/terraform-plan-pr-commenter to version v1.5.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of posting the output of terraform plan as a comment on Pull Requests, helping teams review infrastructure changes directly within their workflow. It supports custom headers for better organization and works with binary plan files for accurate change detection. Additionally, it provides cost impact analysis through CloudBurn, a third-party app that integrates seamlessly with GitHub workflows to provide comprehensive insights into infrastructure changes before they are applied.
July 20, 2026
TrustBeat Anchor — qualified EU timestamps
Version updated for https://github.com/TrustBeat/anchor-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action anchors release artifacts with an eIDAS-qualified timestamp, providing court-grade evidence of artifact existence and integrity. It supports batch processing, secure file hashing, and independent verification through Merkle inclusion proofs and RFC 3161 tokens. The action is designed for use in CI/CD pipelines to ensure regulatory compliance and legal evidence generation without relying on a self-run Timestamping Authority (TSA).
July 20, 2026
Install bashunit
Version updated for https://github.com/TypedDevs/bashunit to version 0.42.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The bashunit GitHub Action is a lightweight, fast testing framework for Bash scripts. It provides numerous assertions, spies, mocks, data providers, and snapshots to simplify testing and improve developer experience. The action supports Bash 3.0+ and can be installed with a simple script and used to test scripts in your project.
July 20, 2026
New Behavioral Health Practices Weekly
Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action downloads and processes behavioral health practice leads from the CMS weekly file, providing a preview or full edition of up to 15 records. It supports free previews using a public dataset without an API token, or fully automated workflows with an Apify account and a token. The action handles states and can set a charge cap for each run.
July 20, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.89.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary miu-cr is an AI code review tool that automates the process of reviewing staged changes, GitHub pull requests, and commits locally or in CI pipelines. It uses LLMs for deterministic analysis and outputs JSON envelopes on stdout, making it suitable for integration into various development workflows. The tool supports local reviews, GitHub PR reviews with inline comments, and can be used as a reusable action in CI pipelines.
July 20, 2026
mdship markdown check
Version updated for https://github.com/verhas/mdship to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mdship, is a command-line and MCP tool for manipulating markdown files. It automates tasks such as fixing heading levels, shifting headings up or down, inserting checksums, reflowing paragraphs, breaking lines at sentence boundaries, numbering headings, adding variables, generating tables of contents, including files, rendering Mermaid diagrams, and using template placeholders. The action ensures consistent content formatting and improves readability by maintaining a hierarchical structure and variable management throughout the markdown document.
July 20, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.720.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a local codebase intelligence tool that automatically analyzes a repository to generate a deterministic code graph, drift score, and ranked upgrade priorities. It helps developers understand their codebase’s dependencies, runtime lag, and EOL proximity, enabling them to identify potential issues and prioritize updates locally. The action runs on the user’s machine without requiring network calls or data leaving the repository unless explicitly pushed.
July 20, 2026
Pixtex — Render n8n Workflow
Version updated for https://github.com/VicegerentPrince/pixtex to version v0.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, pixtex, automates the rendering and hosting of n8n workflow diagrams. It allows users to convert n8n workflow JSON files into share-ready images that update automatically when the workflow changes. The action supports a variety of output formats and can be integrated into CI/CD pipelines to keep documentation up-to-date with the latest workflow configurations.
July 20, 2026
Pixi-Pack Action
Version updated for https://github.com/Wytamma/pixi-pack-action to version v7.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Pixi-Pack Action automates the creation of cross-platform self-extracting binaries for pixi environments. It solves the problem of manually managing and distributing multiple versions of an environment across different platforms by providing a single, easy-to-use action that can be triggered on GitHub releases or workflow dispatches. The action supports macOS, Linux, and Windows and can be used to package environments created with Pixi, making it simpler for users to deploy and manage their applications in various environments.
July 20, 2026
DevSecOps Trust Gate
Version updated for https://github.com/xkobxx/devsecops-dissertation to version v.1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The DevSecOps Trust Gate GitHub Action runs several security scanning tools like Bandit, Semgrep, pip-audit, Trivy, and Gitleaks against a repository to identify potential vulnerabilities. It aggregates these findings into one unified gate with a severity score per finding based on empirical precision data, allowing users to prioritize which issues are worth acting on. The action also provides an HTML dashboard as a build artifact for easy visualization of the scan results.
July 20, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a headless test harness for Claude Cowork skills that reproduces its observable runtime contract across many scenarios, without using the locked Desktop app. It supports both headless and CI environments by providing different fidelity tiers with varying requirements such as running inside Docker or Lima, and supports various platforms including macOS Apple Silicon and Linux.
July 20, 2026
Kover Report Action
Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports both command-based module discovery and glob pattern paths, allows configurable thresholds per module type and name, and integrates with PRs to provide automatic updates on coverage trends. The action also enables tracking coverage history for trend analysis.
July 20, 2026
Vibe-Guard-AICoding
Version updated for https://github.com/YUTAKONDO1205/VibeGuard to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeGuard is a security scanner designed to detect common bugs in AI-generated code. It automates the detection of issues like missing input checks, hard-coded passwords, skipped login checks, and exceptions silently caught. The tool provides inline diagnostics in VS Code, scans code snippets in the browser, and blocks risky PRs in CI using GitHub Actions.
July 20, 2026
Install The Hive Skill
Version updated for https://github.com/yuzuruu29/the-hive-skill to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Hive Skill is a protocol designed to handle multi-model execution in coding hosts. It automates structured handoffs, evidence rules, safety boundaries, and orchestration presets, ensuring that tasks are completed safely and efficiently. The protocol provides explicit stop conditions and bounded repair cycles, making it suitable for agentic coding agents like Claude Code, Codex, OpenCode, and generic workflows.
July 20, 2026
AGENTS.md Lint (Schliff)
Version updated for https://github.com/Zandereins/schliff to version v8.6.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files using Schliff, a tool that provides deterministic quality scores based on a versioned rubric. It helps ensure that AI instruction files remain consistent across different environments and tools by comparing them against an explicit evaluation standard. The action is designed to help identify and address issues in AI instruction files before they degrade over time, ensuring better performance and reliability of AI-driven tools.
July 20, 2026
GSC Opportunity Analyzer
Version updated for https://github.com/demi-valerith/gsc-opportunity-analyzer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action analyzes Google Search Console Performance CSV exports to identify SEO opportunities, such as striking-distance queries, site-relative CTR gaps, and rising demand. It helps prioritize operational work by providing evidence-ledger reports with priority scores and recommendations. The action supports Markdown, JSON, and CSV output formats and integrates with SEO Report Kit for additional insights.
July 20, 2026
easySFTP
Version updated for https://github.com/eiserv/easySFTP to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary easySFTP is a fast, secure, and simple GitHub Actions action that automates the process of uploading build output to any SFTP server. It offers features such as host key verification, atomic file uploads, skip unchanged files, delete safety guards, and multiple target deployments. The action uses a prebuilt Go binary for fast execution and supports Linux, macOS, and Windows runners without requiring Docker.
July 20, 2026
Skip Duplicate Actions
Version updated for https://github.com/fkirc/skip-duplicate-actions to version v5.3.2.
This action is used across all versions by 9,714 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The skip-duplicate-actions GitHub Action provides features to optimize workflows by skipping duplicate runs, concurrent or parallel runs based on content changes, skipping ignored paths for performance, and canceling outdated workflow runs. It helps save time and costs by preventing unnecessary executions of workflows triggered under similar conditions.
July 20, 2026
ReleaseKit – Automated Versioning & Release
Version updated for https://github.com/goosewobbler/releasekit to version v0.41.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseKit automates the release process by integrating with various package registries (npm, crates.io, pub.dev) using Conventional Commits. It provides a unified CLI (release) that can run versioning, notes generation, and publishing in a single command, streamlining the workflow for JavaScript/TypeScript, Rust, and Dart/Flutter packages.
July 20, 2026
action-tag-release-build
Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.11.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action tag-release-build automates the process of bumping a version number, tagging a commit, moving floating major/minor tags, and publishing a GitHub release with a CHANGELOG. It supports semver bump types (major, minor, or patch) inferred from merge/HEAD commits using Conventional Commits, and optionally syncs package.json or Claude Code plugin files.
July 20, 2026
Docker Hub repository description
Version updated for https://github.com/its-me/action.hub.description to version v0.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Hub repository action updates a Docker Hub repository’s short and full descriptions from a markdown file, replacing duplicated configuration across multiple repositories. It automates the process of updating description metadata in Docker Hub, saving time and effort by reducing redundancy in project configurations.
July 20, 2026
Aeroflare CI
Version updated for https://github.com/ItzEmoji/aeroflare to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Aeroflare is a high-performance Nix binary cache proxy that allows developers to store and retrieve Nix packages in an OCI registry. It provides stateless, zero-infrastructure caching with O(1) manifest lookups. The action automates the process of building and pushing Nix outputs to an OCI cache from CI, simplifying package management and reducing build times.
July 20, 2026
Semantic Release by Jedi Knights
Version updated for https://github.com/jedi-knights/go-semantic-release to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The semantic-release action is a production-grade tool written in Go that automates the process of generating semantic versions, creating changelogs, and publishing releases to GitHub. It supports monorepos with independent project versioning and branch policies, including stable releases on main, prereleases on beta/alpha/next. The action parses commit messages to determine release types, calculates next versions based on commit impact, and generates Markdown release notes grouped by commit type. It also provides features like dry-run mode for previewing releases without any mutations and dependency propagation for optional triggering dependent project releases.
July 20, 2026
mdsmith Markdown linter
Version updated for https://github.com/jeduden/mdsmith to version v0.53.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mdsmith action checks and formats Markdown files in a repository using a static Go binary. It automates the process of maintaining consistent Markdown across different files and pipelines, providing auto-fix capabilities to improve readability and structure.
July 20, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.95.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that allows developers to seamlessly integrate various AI providers and models into their applications. It provides a unified API that supports multiple providers such as OpenAI, Anthropic, Google, AWS Bedrock, Azure, and more. NeuroLink offers features like single parameter changes for provider switching, built-in tools, multi-provider failover, intelligent routing, and integration via CLI or TypeScript SDKs. The platform also includes new functionalities for avatar and music modalities, making it versatile for a wide range of applications.
July 20, 2026
datamodel-code-generator
Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.69.0.
This action is used across all versions by 3,338 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action datamodel-code-generator automates the process of generating Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and raw data. It supports converting existing Python types to Pydantic, dataclass, or TypedDict classes, and generates models in different styles such as Pydantic v2, v2 dataclass, dataclasses, and msgspec. The action handles complex schemas and provides type-safe, validated code suitable for IDEs and type checkers.
July 20, 2026
HoverStare
Version updated for https://github.com/liuchong/hoverstare to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review tool for GitHub pull requests that reads your repository like a human reviewer would. It provides a multi-pass voting system with an independent verifier to catch bugs that hide outside the diff, and generates precise inline comments. The action runs as a GitHub Action and can be customized with different models or endpoints.
July 20, 2026
SlimRepo Media Optimizer
Version updated for https://github.com/medoyad/slimrepo-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SlimRepo Media Optimizer Action automates the compression of image files in GitHub repositories to improve performance, reduce costs, and optimize Docker images. It supports PNG, JPG, JPEG, and WebP formats without loss of quality and can be used for free up to 50 files per run or for unlimited use with a PRO license, which includes support for SVG and GIF formats. The action is simple to integrate into GitHub workflows and automatically commits optimized files back to the repository.
July 20, 2026
Mipiti Verify
Version updated for https://github.com/Mipiti/mipiti-verify to version v0.48.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Mipiti-verify is a CI verification tool for Mipiti threat model assertions that automates security controls, ensuring they never drift. It supports both OpenAI and Anthropic AI providers to verify assertions against models, providing options for local Tier 1 verification and offline batch verification from JSON files. The tool also offers features like list, report, audit, and check commands to manage and verify Mipiti assertions effectively.
July 20, 2026
repro-check runnability
Version updated for https://github.com/nelsonjordanme/repro-check to version v0.10.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary repro-check is a tool designed to run old research code and automatically fix issues that cause it to crash. It finds scripts, tries to execute them, and applies known fixes if they break, repeating until the script runs successfully or provides a detailed explanation of where it stopped and what needs to be done next. This helps researchers recreate and verify scientific results from archived papers by automating the process of fixing code rot and dependency issues.
July 20, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.27.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically updates a Go proxy cache by pulling new module versions when tags matching semantic version patterns are created. It supports standard and submodule version tags, custom proxy configurations, and configurable Go versions via setup-go. The workflow can be triggered on GitHub release events and includes options to customize the import path and check for the latest version.
July 20, 2026
Multi-Style Contribution Snake
Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v20.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action multi-style-snake-contribution-grid generates animated snake contributions for a user’s repository, offering 5 distinct styles and shapes. It automates the process of generating multiple snake variations and displays them in an output branch. The action also supports SVGs and GIFs for high-quality rendering and includes a gallery feature to view all assets in one place.
July 20, 2026
TCalc Workspace Report
Version updated for https://github.com/Sandesh13fr/TCalc to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TCalc is a local codebase analysis tool that measures and recommends coding models based on the workspace’s token usage. It automates the process of identifying which models are necessary for coding tasks, provides budgeted repository maps, and generates agent rules to guide development without relying on cloud services or external APIs.
July 20, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates a crew of CLI coding agents to automate tasks deterministically, ensuring reproducible results end-to-end. It uses plain Python scheduling and record-keeping mechanisms without relying on large language models (LLMs). The action provides features such as deterministic multi-agent orchestration, per-artefact lineage tracking, always-on replay journals, and audit logs for traceability and verification.
July 20, 2026
BoundaryCI tenant-isolation scan
Version updated for https://github.com/sir-gig/boundaryci to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local CLI that helps developers catch cross-tenant authorization mistakes in Supabase and PostgreSQL projects by scanning SQL migrations, applying deterministic tenant isolation rules, and optionally using a Fireworks model for review. It catches specific types of security issues related to row-level security (RLS) policies and provides a way to manage baseline findings and waivers.
July 20, 2026
Node Semantic Release
Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.200.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the Node.js release process by installing dependencies, building a project, running semantic-release, and optionally committing and tagging releases. It can be used in two modes: regular release with tag creation or publish mode that creates a GitHub Release from an existing tag using base64-encoded release notes or direct release notes from the tag. The action requires either secrets.GITHUB_TOKEN or a PAT to create tags, and it provides detailed token behavior information for users to choose the appropriate method.
July 20, 2026
hotlane deploy
Version updated for https://github.com/StefanIancu/hotlane-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment process with hotlane from GitHub Actions. It supports various commands such as pushing, testing, promoting, discarding, rolling back, and checking drift between live and source build versions. The action installs hotlane’s binary, runs specified commands with optional arguments, and outputs verification results to the job summary or logs for failed pushes.
July 20, 2026
runward gate
Version updated for https://github.com/stranxik/runward to version v0.21.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward automates the verification of engineering decisions made by AI-generated code, ensuring that all critical design points are followed and documented. It provides a deterministic gate to verify load-bearing decisions and offers comprehensive compliance evidence, making it suitable for ISO 42001, NIST AI RMF, and EU AI Act standards.
July 20, 2026
Keep Node Current
Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Keep Node Current” automates the process of keeping Node.js versions declared across a repository synchronized with the official Node.js release schedule. It updates CI matrix configurations, single-version pins in actions/setup-node, .nvmrc, and package.json files, and opens pull requests for each change. The action ensures that all active even (LTS) majors are included and end-of-life majors are removed, while also managing version floors in engines.node. It provides clear commit and PR titles to reflect the changes made.
July 20, 2026
GitHub Actions Version Audit
Version updated for https://github.com/varunchandak/gh-actions-version-audit to version v1.1.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action audits your repository’s workflows to identify outdated GitHub Actions, mutable action tags, and CI/CD supply-chain drift. It checks each uses: reference against the GitHub API to ensure it points to the most recent release, reporting any version drift or insecure tag pinning. The action can help prevent supply chain attacks by recommending full-length commit SHA pinning and send Slack notifications for any changes.
July 19, 2026
patchnotes changelog validator
Version updated for https://github.com/Londopy/patchnotes to version v2.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The patchnotes GitHub Action parses and validates Keep a Changelog formatted CHANGELOG.md files or YAML changelogs into structured Python objects. It automates tasks such as parsing, diffing changes between versions, validating the format, and rendering changelogs to various formats like HTML, RSS, or plain text. The action is built for use in Python code, shell scripts, and CI/CD pipelines, with pure Python and type support, including YAML parsing.
July 19, 2026
treegen — File Tree for README
Version updated for https://github.com/lucianofedericopereira/treegen to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts Markdown files into a directory tree, providing options to render the tree in ASCII, SVG, or collapsible format, with support for descriptions and excluding certain files. It supports themes for SVG rendering and can be integrated into any repository without additional dependencies.
July 19, 2026
SecureSoroban
Version updated for https://github.com/mammumammi/Secure-soroban-marketplace-Action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SecureSoroban automates the detection of critical vulnerabilities in Soroban smart contracts by simulating real attack vectors, confirming what actually breaks, and calculating estimated financial loss in XLM and USD. It helps prevent vulnerabilities from reaching mainnet and blocks deployment automatically if critical issues are found. SecureSoroban also includes a local AI agent powered by Qwen2.5-coder:7b for more advanced analysis and targeted attacks.
July 19, 2026
guardmarly
Version updated for https://github.com/mattybellx/Guardmarly to version v6.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Guardmarly is a static analysis tool that focuses on identifying and flagging common security issues related to authorization gaps and risky code paths, such as IDOR (Insecure Direct Object Reference) vulnerabilities. It analyzes HTTP routes, checks for authentication guards, and traces data flow to potential sinks, helping developers identify and address these critical security flaws in their applications.
July 19, 2026
Mipiti Verify
Version updated for https://github.com/Mipiti/mipiti-verify to version v0.47.3.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Mipiti-verify automates the verification of Mipiti threat model assertions using AI models, offering local and online verification options. It supports OpenAI and Anthropic models for Tier 2 verification and provides a command-line interface for running and checking individual assertions locally. The action also includes features to list and report on pending and verified assertions, as well as audit signed reports for integrity and provenance.
July 19, 2026
Upload UI Evidence
Version updated for https://github.com/mtzack-org/upload-ui-evidence to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading UI test evidence from CI/CD pipelines to a private UI Evidence Portal. It supports various testing frameworks like Playwright, Maestro, and Appium, allowing you to visualize and share screenshots, videos, reports, traces, and logs directly from your CI job summaries. The action provides flexibility in specifying which files to upload and handles cases where no evidence is found by configuring the behavior via output options.
July 19, 2026
lacuna-cli
Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lacuna is a command-line tool that automates the process of writing unit and integration tests for untested code in your project using OpenAI-compatible models. It reads your existing code, identifies parts without coverage, generates corresponding test cases, runs them, and retries those that fail. This ensures that what lands in your repository actually passes, while maintaining the quality of your tests through continuous refactoring.
July 19, 2026
Otzaria Plugin Validator
Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action validates and automatically publishes an Otzaria plugin to the store upon pushing changes to the main branch, ensuring that only updates are published after approval from store administrators. It supports multiple plugins in a monorepo and requires API reference URLs for dynamic validation. The action can run as a pull_request check without publishing by default, but requires secrets for automated publication.
July 19, 2026
OWASP Noir Action
Version updated for https://github.com/owasp-noir/noir to version v1.2.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages the Noir SAST tool to identify and document all exposed endpoints in code, including parameters, headers, cookies, and the source files behind them. It supports various languages and frameworks, provides AI context for LLM-based SAST, and integrates with DAST tools like ZAP, Burp Suite, and Caido. The action is designed to be integrated into CI/CD pipelines and can output results in multiple formats.
July 19, 2026
rl-package
Version updated for https://github.com/rl-lang/rl-package to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rl-package GitHub Action packages an .rl source file into a self-contained binary for Linux, macOS, or Windows using the RL language and uploads it as a workflow artifact. It solves the problem of automating the packaging process for RL programs in CI/CD pipelines by providing a simple configuration interface to specify input parameters such as the source file path and output name. The action supports caching for quick repeat runs and is compatible with various runners including Ubuntu, macOS, and Windows.
July 19, 2026
AAB to APK with Bundletool
Version updated for https://github.com/roberteggl/bundletool-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Bundletool Action is a GitHub Action that automates the conversion of Android App Bundles (.aab) to APKs using Google’s bundletool. It automatically downloads and caches bundletool with version pinning, supports both universal APK generation and device-specific APK extraction, provides optional APK signing from a keystore path or base64 GitHub Secret, and includes features like dry-run and verbose logging. The action validates configuration inputs and masks secrets in logs for enhanced security.
July 19, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.37.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter built with Rust. It offers speed, extensive linting rules (76 in total), automatic formatting, and multiple Markdown flavors support. The action simplifies the process of checking and fixing markdown files, making it easier to maintain consistency across projects.
July 19, 2026
TCalc Workspace Report
Version updated for https://github.com/Sandesh13fr/TCalc to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TCalc is a local tool that measures and recommends models and context for coding agents. It analyzes a workspace to identify token-heavy files, folders, and languages, comparing them against different models to generate budgeted repo maps and agent rules. The tool respects workspace ignore rules and can be used in VS Code or as a CLI tool.
July 19, 2026
seekrit — load secrets
Version updated for https://github.com/seekritdev/github-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of loading secrets from seekrit, a secure secret management tool. It decrypts secrets locally using a private key associated with a service token and injects them into subsequent steps as environment variables, ensuring that sensitive information is not exposed in logs or visible to other team members. The action supports various configurations such as prefixing variable names, filtering which secrets to include or exclude, and exposing secrets as step outputs.
July 19, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is a GitHub Action that automates the process of code reviews using AI. It runs multiple specialized AI reviewers in parallel, providing a more comprehensive view than relying on a single model. The action uses an evidence-based curator to verify findings before posting review comments on pull requests, ensuring only valid issues are highlighted. This approach helps in finding more real bugs while minimizing false positives.
July 19, 2026
ifttt-lint
Version updated for https://github.com/simonepri/ifttt-lint to version v0.10.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ifttt-lint automates the catchment of cross-file drift by enforcing consistent changes across related codebases through comments. It helps in maintaining synchronization between different programming languages, databases, and APIs to prevent issues that arise from uncoordinated updates. The action supports GitHub Actions for push and pull_request events, pre-commit hooks, and manual installation via Cargo.
July 19, 2026
SJ_TEST Giphy PR Comments
Version updated for https://github.com/SJWarrior-17/js_pr-giphy-comment to version alpha-v1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the addition of a Giphy GIF comment to new pull requests in a GitHub repository. It simplifies the process by using Node.js and the @octokit/rest package to interact with the GitHub API, along with the giphy-api package to fetch a random GIF from the Giphy service. The action is configured to accept input parameters for GitHub token and Giphy API token, ensuring that it can be easily integrated into various repositories to enhance communication and engagement during pull requests.
July 19, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.8.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight read-only viewer for OpenSpec content that automates tasks such as browsing specs, changes, and tasks with structure. It solves problems related to managing parallel worktrees in AI-agent environments by aggregating all in-flight changes into one view, providing full-text search capabilities, and offering a responsive layout across various screen sizes.
July 19, 2026
runward gate
Version updated for https://github.com/stranxik/runward to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is a tool that automates the verification of engineering decisions made by AI-generated code. It checks whether the architectural, security, and operational aspects were correctly implemented during the development process. By running the deterministic gate, Runward ensures that the load-bearing decisions are accurately recorded and can be verified deterministically without relying on an LLM.
July 19, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.4.
This action is used across all versions by 138 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a dependency manager for TOML files in your GitHub Actions workflows. It allows users to install Tombi and its dependencies efficiently, with options for specifying specific versions, using lock files, enabling checksum verification, and configuring cache behavior.
July 19, 2026
Setup Upwarden
Version updated for https://github.com/upwarden-io/setup-upwarden to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-upwarden GitHub Action automates the authentication and authorization of package manager dependencies, enabling keyless OIDC access to private registries. It ensures that every dependency fetch in a CI pipeline is authenticated, attributed, and policy-enforced, mitigating security risks associated with unauthenticated and unattributed package fetches. The action works seamlessly across various toolchains (npm, pnpm, yarn, pip, maven, gradle) and provides a simple setup process to integrate OIDC authentication into your CI pipelines.
July 19, 2026
Premature Contribution Firewall dry-run
Version updated for https://github.com/VrtxOmega/premature-contribution-firewall to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Premature Contribution Firewall automates the review-readiness assessment of pull requests and patches, helping maintainers prioritize actionable tasks before submission. It ensures that contributions meet key criteria such as reproducibility, scope, testing, and worth human attention, reducing the workload by focusing on issues most likely to be beneficial for the project.
July 19, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the testing of Claude Cowork skills in a headless and CI-friendly manner. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. Key features include:
July 19, 2026
Open License Auditor
Version updated for https://github.com/yanovian/open-license-auditor to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Open License Auditor GitHub Action automates the process of identifying and flagging potentially problematic open source licenses in a repository. It supports various package managers, checks dependencies (direct and indirect), and provides detailed reports about any risky licenses found on pull requests. The action can be configured to filter results based on severity, fail the build if critical issues are detected, and optionally post comments with the audit report.
July 19, 2026
PR Rigor
Version updated for https://github.com/Hassan7253/pr-rigor to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Rigor automates deterministic checks to ensure that pull requests are prepared for focused human review. It identifies missing context, tests, security issues, supply chain problems, release readiness, and compatibility, providing clear evidence and recovery steps. The action is designed to help maintainers keep final authority over pull request acceptance, using repeatable first-pass checks with a stable GitHub comment update.
July 19, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, account takeovers, and over 350 threat indicators across various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and GitHub repositories. It generates CycloneDX 1.6 SBOMs with real dependency inventories, parses and validates in-toto/DSSE attestations, and correlates findings into attack-chain incidents.
July 19, 2026
ASCII profile card
Version updated for https://github.com/hu553in/ascii-profile-card to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats, automating the process of maintaining up-to-date profile information in a dedicated branch. It supports customizable configurations through inline YAML documents and provides dark and light variants for easy integration into profiles. The action ensures that the generated files are updated regularly, enhancing user experience by keeping their profiles fresh.
July 19, 2026
droast — Dockerfile linter
Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary of the droast GitHub Action
The droast GitHub Action is a lint tool that checks Dockerfiles for best practices and potential issues, providing real-time feedback to developers during development. It can catch malformed syntax and catches bad practices in the Dockerfile, offering clear messages about these problems. The action works by analyzing the Dockerfile using a parser that understands various aspects of Dockerfiles, including heredocs, shell forms, Windows paths, and PowerShell.
July 19, 2026
Invigil — Product Quality Gate
Version updated for https://github.com/invigil/invigil to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that grades open-source projects against a product-quality doctrine by checking if the project boots, reads, and fixes errors in ten minutes. It ensures legibility, error hygiene, and supply-chain security through various gates and tools like linters, dependabot, and OpenSSF Scorecard.
July 19, 2026
zizmor - static analysis tool for Actions workflows
Version updated for https://github.com/its-me/action.zizmor to version v1.0.1.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs the zizmor static analysis tool on GitHub Actions workflows. It automates finding security issues in workflows, providing inline annotations and SARIF files when code scanning is enabled, or simply streaming findings to the job log otherwise. The action uses a Docker image based on its own checked-out files, ensuring consistent behavior across different repositories calling it.
July 19, 2026
Lazaretto Scan
Version updated for https://github.com/jamesdfinance-dev/lazaretto-scan-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lazaretto Scan GitHub Action automatically checks npm packages, repositories, skills, or files for malicious behavior by sending them to the Lazaretto API. It fails the build if any target is marked as “malicious” or “flagged,” providing a clear verdict in a sticky comment on pull requests. The action supports scanning specific targets or using the package.json file by default, and it integrates with GitHub Actions for CI/CD integration.
July 19, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is an AI coding agent guardrail that blocks common secret leaks before they happen, protecting sensitive information like .env files and credentials from accidental exposure. It uses gitleaks for detection and shell scripts for integration, with support for Claude Code, Codex, Git hooks, CLI usage, and more.
July 19, 2026
Check Empty Files
Version updated for https://github.com/jonathandung/check-empty to version 0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if specified files are empty and clears them if they are. It automates the process of ensuring that certain files remain empty, which can be useful for maintaining consistency across projects or environments. The action is also available as a CLI tool and library, allowing for flexibility in how it is used within different development workflows.
July 19, 2026
Landsafe — Postgres migration safety
Version updated for https://github.com/landsafe-dev/action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Landsafe GitHub Action checks PostgreSQL migration PRs for potential issues that could cause downtime on production, such as blocking index builds or full table rewrites. It analyzes the .sql files in the PR diff and provides warnings about critical risks before merging the changes. The action does not connect to the database and is designed to be used alongside schema-as-code tools.
July 19, 2026
move-test-gen coverage check
Version updated for https://github.com/mehvetero/move-test-gen to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The move-test-gen GitHub Action generates edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic issues. It uses the skills CLI to install and integrates into Claude Code environments, allowing users to generate tests by inputting function sources or audit findings. The coverage checker verifies that all asserts have corresponding expected failures and catches injected bugs using mutation testing.
July 19, 2026
Mipiti Verify
Version updated for https://github.com/Mipiti/mipiti-verify to version v0.47.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mipiti-verify, automates the verification of threat model assertions for Mipiti tools. It can verify assertions against OpenAI or Anthropic models or check them locally using Tier 1 controls. It supports multiple commands including running all models, verifying a single assertion, checking assertions from a JSON file, listing pending assertions, reporting results, and auditing signed reports. The audit envelope contract ensures the integrity and authenticity of the verification results by leveraging public cryptographic chains and signatures.
July 19, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that provides a zero-LLM linter and a queryable knowledge index derived from plain markdown lessons. It ensures project lessons, rules, and context survive across sessions by keeping them in the repository alongside the code. The tool is designed to prevent architectural mistakes by enforcing best practices with deterministic linting rules and a local, offline knowledge index.
July 19, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.13.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action that audits AI harness files to ensure consistency, reliability, and security. It helps consolidate scattered guidance into one canonical AGENTS.md, keeps tool-specific files as small pointers, and measures whether the resulting harness actually improves agent answers. The action checks for various issues such as duplicate instructions, conflicts, security vulnerabilities, and incorrect permissions.
July 19, 2026
Droidwatch APK Scan
Version updated for https://github.com/Omar1123/droidwatch-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action scans Android APKs for malware and threats, using the Droidwatch platform. It uploads the build artifact to Droidwatch for analysis and fails the build if a malicious verdict is detected. The action provides outputs like verdict, risk score, and report URL. Users can configure fail-on-verbs and set a timeout for analysis.
July 19, 2026
railward
Version updated for https://github.com/Ourbando/railward to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Railward is a deterministic guardrail that automatically tests and validates AI policies. It runs predefined attack scenarios against the policy to ensure it behaves as expected. The action provides signed, hash-chained logs of allowed, blocked, and leaked actions, allowing users to verify the policy’s compliance and detect potential vulnerabilities.
July 19, 2026
raviqqe/muffy
Version updated for https://github.com/raviqqe/muffy to version v0.3.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a tool for validating static websites, similar to the muffet CLI. It automates the process of checking website structure and accessibility, helping developers ensure their sites meet quality standards. The action provides features like checking for broken links, duplicate content, and HTML errors, which can be integrated into CI/CD pipelines to maintain website quality continuously.
July 19, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.52.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security scans for AI agent pipelines, providing offline determinism and auditor-ready compliance-evidence packs. It finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 13 agent platforms. The action ensures consistent findings and produces comprehensive SARIF reports mapped to 13 security frameworks and compliance regimes.
July 19, 2026
Setup BATS
Version updated for https://github.com/sgerrand/setup-bats-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of BATS (Bash Automated Testing System) in a workflow, allowing for easy testing of Bash scripts. It resolves the latest release version or allows pinning to specific versions using a token for API calls, providing outputs for the installed version and supporting examples on how to use it.
July 19, 2026
BoundaryCI tenant-isolation scan
Version updated for https://github.com/sir-gig/boundaryci to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local-first CLI that scans Supabase and PostgreSQL projects for security issues related to tenant isolation in RLS rules. It checks for exposed tables without RLS, missing or incorrect policies, and identifies potential bypasses by SECURITY DEFINER functions. BoundaryCI can also review policy interactions using a Fireworks model if configured, providing insights into how different policies interact. The tool is designed to help catch errors before a migration reaches production and offers features for baselining and managing security findings.
July 19, 2026
Skaphos Oiax
Version updated for https://github.com/skaphos/oiax to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Oiax is a GitOps tool that reconciles promotion requests between long-lived branches in Git repositories, ensuring each branch has only one active pull request promoting changes to the next environment. It automates branch-based environments and handles backflow from production to development.
July 19, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.55.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console CensorChecker: 这是一个基于 PowerShell 的 TCPing 批量拨测脚本,主要用于检查网络是否被审查设备拦截。它适用于任何平台,并且旨在帮助开发者监控和测试服务的可用性,同时遵守相关法律法规。通过该脚本,用户可以自动化检测目标主机的响应时间,以便在潜在的审查环境中进行验证。
What’s Changed 添加 Test Checker 工作流 添加 Module、Script、MCPB 的发布工作流 添加 Check Censor 工作流 修改 Invoke-Check 输出为 target-latency 键值对 修改 Action 结果聚合为 hashtable 合并 修改 App 结果对象构造为普通 hashtable 属性袋 移除 Action 中的无效依赖
July 19, 2026
GuardLine Security Scan
Version updated for https://github.com/toutlawbradley/GuardLine to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardLine is a GitHub Action designed to perform security scans on pull requests, focusing on secrets detection, dependency vulnerabilities, configuration risks, code patterns, and permission issues. It posts findings in the PR comment and SARIF format, allowing for easy visibility of potential security risks. The action supports three scan levels: quick, standard, and deep, with the standard level being the default for most repositories.
July 19, 2026
Open License Auditor
Version updated for https://github.com/yanovian/open-license-auditor to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Open License Auditor automates the identification of risky open-source licenses in a repository’s dependencies. It supports various package managers and scans all dependencies to flag any license that could pose security or licensing risks. The action posts comments on pull requests, listing risky dependencies and providing full dependency maps for further inspection.
July 19, 2026
MCPScan by yyyutakaaa
Version updated for https://github.com/yyyutakaaa/mcpscan to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary mcpscan is an automated security tool designed to detect common security issues in machine learning models and related configurations, such as injection attacks, dangerous code execution, misconfigured servers, exfiltration vulnerabilities, supply chain risks, and secrets exposure. It analyzes Python scripts, configs, and skill folders to provide detailed reports on potential security weaknesses, helping developers prevent threats before they reach their models.
July 19, 2026
terraform-plan
Version updated for https://github.com/dflook/terraform-plan to version v3.0.0.
This action is used across all versions by 369 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This Terraform action generates and optionally comments on a plan for a given Terraform project. It supports PRs by adding comments with the generated plan, automating the creation of plans for other events, and providing options to customize variables, backend configurations, and resource targeting. The action is part of a suite of actions for managing Terraform projects in GitHub Actions.
July 19, 2026
terraform-validate
Version updated for https://github.com/dflook/terraform-validate to version v3.0.0.
This action is used across all versions by 605 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Terraform validation by running the terraform validate command to check that a Terraform configuration is valid. It can detect and fail builds if the configuration contains syntax errors or other issues before attempting a plan. The action supports specifying workspace, backend configurations, and environment variables for customizing the validation process.
July 19, 2026
terraform-version
Version updated for https://github.com/dflook/terraform-version to version v3.0.0.
This action is used across all versions by 25 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action determines and outputs the Terraform version to use based on various sources including cloud workspace configurations, module configuration, environment variables, and available binaries. It supports both Hashicorp’s Terraform and OpenTofu, automatically discovering the appropriate version for a given Terraform root module.
July 19, 2026
Composite Linter
Version updated for https://github.com/georglauterbach/linter to version v0.4.1.
This action is used across all versions by 6 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action runs multiple linters, including Actionlint, EditorConfig Checker, Hadolint, Shellcheck, YAMLLint, and Zizmor, to analyze various files such as GitHub CI/CD workflows, EditorConfig configurations, Dockerfiles, shell scripts, YAML files, and GitHub workflows. It allows users to disable specific linters or provide custom configuration files and arguments for each linter.
July 19, 2026
ReleaseKit – Automated Versioning & Release
Version updated for https://github.com/goosewobbler/releasekit to version v0.40.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseKit is an automated tool that automates the process of releasing npm packages, crates.io libraries, and Dart/Flutter packages. It uses Conventional Commits to generate changelogs and version numbers, and supports CI-native workflows with JSON output and OIDC publishing. The action provides three independent CLIs for versioning, generating notes, and publishing packages, making it flexible for different ecosystems and projects.
July 19, 2026
ASCII profile card
Version updated for https://github.com/hu553in/ascii-profile-card to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats. It automates the creation of a dedicated branch for generated files, which can be embedded in a profile README. The action supports various card configurations, including header, section, key/value, and blank rows, allowing users to customize the appearance of their profile cards.
July 19, 2026
Codex Action
Version updated for https://github.com/icoretech/codex-action to version v0.9.22.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Action automates the execution of OpenAI’s Codex CLI in GitHub Actions workflows using a containerized version of the tool. It supports both API key and OAuth/Device Auth authentication methods, offering flexibility depending on user preferences and needs. The action simplifies integration with Codex for tasks such as summarizing changes or generating text, providing a clean and automated way to leverage Codex’s capabilities within GitHub Actions pipelines.
July 19, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cibuild, automates the setup of CI/CD pipelines for iOS and Android projects. It provides an interactive wizard for creating and customizing workflows using YAML files, which can be run locally or on remote runners with AI agents. The action supports auto-detection of platforms, secret management, and pipeline validation, facilitating a streamlined development process for mobile applications.
July 19, 2026
riskratchet
Version updated for https://github.com/KayhanB21/riskratchet-action to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a wrapper for KayhanB21’s riskratchet maintainability ratchet tool, designed to help with automated code reviews in AI-assisted Python projects. It allows users to integrate riskratchet into their workflows using GitHub Actions without needing to clone and install the riskratchet package directly. The action automates the process of checking code for maintainability issues based on coverage data provided by tools like Coverage.py, making it easier to maintain high-quality Python code in AI-driven projects.
July 19, 2026
OSS Warrior
Version updated for https://github.com/masatohoshino/oss-warrior to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The OSS Warrior GitHub Action measures an account’s OSS power level across three domains: CONTRIBUTOR, MAINTAINER, and SOLO, and displays it as a living warrior card. The action automates the process of tracking public GitHub events to generate a reproducible card without requiring sign-up or additional servers.
July 19, 2026
Sentrik Gate
Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentrik is a governance runtime that automates compliance checks on AI-generated code. It enforces coding standards, security policies, and compliance rules before code ships by scanning every change against regulatory standards and gating PRs that fail. The free tier includes 6 standards packs with 193 rules for free, while paid tiers offer more features like OWASP, SOC 2, and supply chain standards. Sentrik integrates seamlessly with GitHub Actions to enforce gates in CI/CD pipelines, providing a comprehensive solution for AI-generated code quality and governance.
July 19, 2026
Miso PR Review
Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.5.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically reviews pull requests using a language model, providing detailed feedback on the code changes and potential risks. It uses OpenAI-compatible models or local models hosted on platforms like llama.cpp, vLLM, LiteLLM, or Anthropic to generate comments and decide if further action is needed for security or risk classification. The action supports CI checks, structured findings with severity tagging, and can publish reviews as sticky comments or native GitHub reviews. It optimizes token usage through incremental review processing and safe defaults, ensuring a seamless AI-driven PR review process.
July 19, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.35.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, litmus, is designed to automate the process of evaluating and grading MCP servers based on their behavior. It connects to an MCP endpoint, runs a set of probes to evaluate the server’s performance, and provides a grade along with evidence files. The action can be used for both lookup and execution purposes, allowing users to quickly assess server capabilities and reproduce grades.
July 19, 2026
embd-check
Version updated for https://github.com/ptsouchlos/embd to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary embd is a CLI tool designed to manage embedded repositories within a project, providing an alternative to git subtree and git submodule. It automates the process of cloning and updating dependencies, while also allowing for selective filtering of content. This helps in maintaining clear separation between project code and its dependencies and ensures that all changes are tracked in version control. The tool is particularly useful for managing Git submodules within larger projects to improve maintainability and simplify deployment processes.
July 19, 2026
raviqqe/muffy
Version updated for https://github.com/raviqqe/muffy to version v0.3.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static website validator that automates the process of checking for errors in HTML, CSS, and JavaScript files used to build websites. It solves the problem of manual validation by providing automated checks during the build process, helping developers catch issues early before deploying their sites. The action provides capabilities to validate HTML structure, missing alt text, SEO compliance, and more.
July 19, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.36.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Rust-based Markdown linter and formatter with over 76 lint rules, offering automatic formatting and zero dependencies. It’s built for speed and supports multiple Markdown flavors, including GFM, MkDocs, MDX, Quarto, and MyST. The tool is highly configurable through TOML files and integrates well with various editors and CI/CD pipelines.
July 19, 2026
SJ_TEST Giphy PR Comments
Version updated for https://github.com/SJWarrior-17/js_pr-giphy-comment to version alpha-v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to automatically add a Giphy GIF comment to new pull requests in a multi-node Kubernetes 1.34 environment. It automates the process of generating and posting a relevant GIF to help newcomers and contributors feel welcome. The action uses Node.js, Octokit for interacting with GitHub’s API, and Giphy’s API to fetch and display a GIF comment on a new pull request.
July 19, 2026
Skaphos Oiax
Version updated for https://github.com/skaphos/oiax to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Oiax is a declarative Git branch promotion reconciler for GitOps repositories. It ensures that pull requests exist between adjacent branches to move changes through an environment graph, automating the management of environment promotion requests and backflow. The action supports GitHub Actions and requires git 2.45 or newer for its functionality.
July 19, 2026
vibestats
Version updated for https://github.com/stephenleo/vibestats to version v2.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeStats is an open-source GitHub Action that tracks Claude Code and Codex sessions to provide users with a heatmap on their GitHub profile and a full analytics dashboard at vibestats.dev/<username>. It synchronizes aggregated daily stats to a private GitHub repo, ensuring history past 30 days without changing Claude Code’s default settings. The action helps users keep track of usage trends, privacy, and survival across machine wipes and reinstalls, offering detailed metrics such as tokens, sessions, minutes, model breakdowns, harness mixes, and more.
July 19, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.3.
This action is used across all versions by 138 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a package manager for TOML files, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions using lockfiles like uv.lock. The action supports checksum verification for both the archive and binary binaries, ensuring the integrity of the installed version.
July 19, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.89.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary miu-cr is an AI code review tool designed for the CLI, CI, and MCP hosts. It automates code reviews locally, gates PRs in CI, or drives the engine from any MCP-capable agent. The tool provides deterministic engine functionality, stable JSON envelopes on stdout, and supports local review, GitHub PR review, and CI/GitHub Action integration with project rules and evaluation capabilities.
July 19, 2026
Pixtex — Render n8n Workflow
Version updated for https://github.com/VicegerentPrince/pixtex to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the conversion and hosting of n8n workflow JSON into interactive diagrams using Pixtex, a web-based diagramming tool. It allows developers to render local images, host them as permanent URLs with stable IDs, update existing diagrams in CI workflows, and embed them directly in documentation or other platforms. The action simplifies the process by rendering the workflow at build time and automatically updating it in place whenever changes are pushed to the repository.
July 19, 2026
luacheck for FiveM - WTP
Version updated for https://github.com/We-The-People-RP/fivem-lua-lint-action to version V2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically runs luacheck on a developer’s Lua codebase to ensure compliance with FiveM coding standards. It supports the use of backtick syntax and provides options for generating JUnit reports, which can be used to visually display linting results in GitHub Actions workflows.
July 19, 2026
Move Closed Issue to Top of Project Column
Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.21.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of moving closed issues to the top of a specified column in GitHub Project V2. It checks if an issue belongs to a specific project and updates its status to a given column, ensuring recently closed issues are visible at the top of the project board. The action supports multiple projects with different settings and requires a GitHub token with project and repo permissions.
July 19, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a scriptable test harness designed to simulate and reproduce the observable runtime contract of Claude Cowork’s skills. It helps in testing local skills without using the locked Desktop app, across various scenarios and CI jobs. The action supports different fidelity tiers with varying requirements including Node.js version, Python (for linting), and a running runtime for live tests. It is designed to mimic the limitations of Cowork, such as sealed filesystems and default-deny egress, ensuring green tests reflect real-world behavior.
July 18, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.514.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security and quality checks of AI plugins across different coding environments (Codex, Claude, Gemini, OpenCode) by emitting structured reports. It helps identify potential security issues, code readability concerns, and runtime readiness, while staying aligned with the main scanner release train. The action supports various execution modes and output formats, making it versatile for developers to integrate into their workflows.
July 18, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns and fake AI tool repos across various ecosystems, including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It uses a combination of threat indicators and automated analysis to provide a comprehensive view of the security posture in your software supply chain.
July 18, 2026
droast — Dockerfile linter
Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action droast-dockerfile-linter automates Dockerfile linting by identifying and reporting bad practices, providing feedback in a non-polite manner. It supports various parsing capabilities, including handling heredocs, parser directives, shell forms, BuildKit flags, Windows paths, PowerShell, and custom ignore files to ensure accurate detection of issues.
July 18, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild action automates the setup and configuration of CI/CD pipelines for iOS and Android projects using YAML files. It provides an interactive wizard or auto-creation feature to generate a ready-to-use GitHub Actions workflow, which is fully non-interactive and works with AI agents and scripts. The action also supports importing existing pipeline YAML files and allows customization by editing the generated pipeline files.
July 18, 2026
Invigil — Product Quality Gate
Version updated for https://github.com/invigil/invigil to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that evaluates an open-source project against product-quality guidelines, not just code style. It checks whether the published artifact boots quickly and legibly, ensuring cold-start users can easily use and contribute to the project. Invigil provides detailed feedback on what’s wrong, why it matters, and how to fix it in CI. The tool covers gaps left by existing tools like linters and dependabot, focusing on legibility and error hygiene.
July 18, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a guardrail for AI coding agents (Claude Code, Codex) to prevent accidental exposure of secrets before they are read or written. It uses gitleaks for detection and plain shell scripts for integration. By running at the agent’s tool boundary, it blocks common ways an agent can accidentally expose secrets and provides defense in depth by also performing commit- or CI-time scanning.
July 18, 2026
jPipe Runner
Version updated for https://github.com/jpipe-mcscert/jpipe-runner to version v3.5.3.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A Justification Runner designed for jPipe, which automates template variable definitions, library loading, diagram selection, output file specification, dry run validation, and debug logging for jPipe workflows. It supports command-line interface usage with various options like variable definition, diagram selection, output file path, and more.
July 18, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.93.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that provides a TypeScript-first way to integrate with 30+ AI providers and 100+ models. It offers single, consistent APIs, support for edge-first execution, continuous streaming architectures, and enterprise features such as Redis memory and multi-provider failover.
July 18, 2026
kramlipi CI Repair
Version updated for https://github.com/kramlipi/code-agent-action to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, kramlipi/code-agent-action, automates CI verification and repair processes by running a specified command (verify-cmd) to check the status of a workflow run. It ensures that the build is green before proceeding with further tasks or generating a draft pull request if specified. The action supports various expert modes for different types of fixes, such as bug-fixing, code-review, and testing intelligence. It also manages secrets for authentication and licensing with options for free CI to paid upgrades via license API.
July 18, 2026
HoverStare
Version updated for https://github.com/liuchong/hoverstare to version v0.0.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review tool for GitHub that reads your repository like a human reviewer before making suggestions. It uses multi-pass voting and a verifier to ensure high signal, low noise. The action provides precise inline comments with line number validation and incremental reviews, while being fail-open by design.
July 18, 2026
guardmarly
Version updated for https://github.com/mattybellx/Guardmarly to version v6.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Guardmarly is a free SAST tool that automates the detection of authorization bugs such as IDOR, missing access controls, and privilege escalation. It maps HTTP routes to database queries and checks for missing auth guards, tracing data flow from routes to sinks to flag security vulnerabilities. Guardmarly provides detailed reports in text, JSON, and SARIF formats and supports multiple programming languages and CWEs, including 5 languages and 35+ CWE types.
July 18, 2026
Affected Code Owners
Version updated for https://github.com/meddevo/affected-codeowners to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action affected-codeowners determines which code owners are affected by changes in a pull request based on the repository’s CODEOWNERS file. It parses the file to generate lists of individual and grouped code owners, addressing known limitations related to pattern escaping and negation. The action outputs JSON-formatted lists of affected owners for both individuals and groups, aiding in tracking which contributors need attention.
July 18, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.19.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action is a tool to locally execute and test Salesforce Apex code. It supports running tests, executing anonymous Apex, and debugging Apex in an interactive debugger through CLI or CI. It mimics the Salesforce runtime environment locally, without requiring an org or deploy. The action can be installed as a Homebrew package, npm plugin, VS Code extension, or downloaded manually.
July 18, 2026
Automatic Semantic Releases
Version updated for https://github.com/oliversalzburg/action-automatic-semantic-releases to version v3.2.0.
This action is used across all versions by 16 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically creates semantic releases based on versioning in code. It supports tagged builds, version management, and development builds with customizable release settings. The action uses the release-version.cjs script to generate versions and can be configured to create draft or prerelease releases.
July 18, 2026
Install omnipackage
Version updated for https://github.com/omnipackage/omnipackage-rs to version v0.1.17.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and configures the OmniPackage CLI for building RPM, DEB, and Arch packages. It automates the process of packaging software into these formats using a specified channel (stable or master). The action is designed to be used in workflows on Ubuntu runners, automatically detecting the CPU architecture.
July 18, 2026
GitHub Change Risk
Version updated for https://github.com/orangevakaris/github-change-risk to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action checks for risks in changes between two commits without running the repository’s code, providing deterministic risk signals and aggregate reports. It supports free and paid per-file reports, is opt-in for commenting on pull requests, and requires API access to function.
July 18, 2026
Self-hosted Repository Visuals
Version updated for https://github.com/overtrue/repo-visuals-action to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action generates star history charts and contributor walls from GitHub’s API without using third-party rendering services, providing customizable themes and offline SVGs with embedded avatar images. It supports multiple chart types (area, line, glow) and various themes, including classic and gradient styles, with a focus on determinism and offline capabilities for local rendering.
July 18, 2026
PR Explainer AI
Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Explainer AI is a GitHub Action that automates the creation of interactive HTML artifacts for pull requests. It helps reviewers understand pull requests by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes, making the knowledge durable and easy to revisit. The action supports multiple languages and limits large changes to avoid model issues.
July 18, 2026
ForgeProof Verify
Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, forgeproof-verify, automates the verification of ForgeProof .rpack provenance bundles on pull requests. It ensures that the bundles are tamper-proof and integrates with CI to ensure complete integrity and completeness of sealed provenance chains and artifacts within the checkout. The action posts a human-readable audit report as a PR comment and writes it to the job summary, helping to maintain the veracity of AI-generated code in open-source projects.
July 18, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI code review tool that optimizes for recall by running multiple specialized AI reviewers in parallel. It uses an evidence-based curator to verify findings before posting review comments on pull requests, helping developers identify more real bugs while keeping false positives manageable. The action supports various LLM providers and allows users to create custom lenses using Markdown.
July 18, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.7.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents, scheduling tasks using plain Python to ensure reproducibility. It records every artifact write in an always-on lineage spine and replay journal, providing audit logs with receipts for offline verification.
July 18, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw is a tool designed to streamline and automate Go monorepo management. It automates the creation, synchronization, and verification of a go.work file across multiple modules, ensuring consistent dependency versions and streamlined workflows. The main functionalities include bootstraping, linting, running commands in parallel, generating documentation, and analyzing module dependencies to identify changes affecting the project as a whole.
July 18, 2026
EcoTrace Carbon Gate
Version updated for https://github.com/Zwony/ecotrace to version core-v1.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EcoTrace is a lightweight library designed to measure the carbon footprint of Python applications in real-time. It provides features such as pausing and resuming tracking, side-by-side run comparisons, webhook integrations, filtered CSV exporting, log maintenance commands, and access to session metrics programmatically. The action automates energy and emissions instrumentation without requiring configuration files or background services.
July 18, 2026
Sparda MCP
Version updated for https://github.com/zyx77550/sparda to version v0.64.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles backend behavior into a graph, enabling automated validation and testing of web applications. It provides a way to ensure that your application’s logic remains consistent and free from errors without relying on external APIs or tools. The compiled behavior graph can be used by AI agents to automate tests, debug issues, and prevent breaking changes during deployments.
July 18, 2026
efaimo
Version updated for https://github.com/efaimo-ai/efaimo to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The efaimo action is a tool designed to audit and validate Agent Skills and MCP servers. It checks the context budget, trigger quality, linting errors, and migration diffs against the 2026-07-28 spec. Additionally, it provides a way to measure whether a skill improves task completion using A/B testing with LLM judges. The tool is useful for developers to ensure that their agent’s skills are well-formed, efficient, and effective.
July 18, 2026
rust-star-history
Version updated for https://github.com/Flux159/rust-star-history to version v1.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rust-star-history GitHub Action generates self-hosted star history SVG charts for any GitHub repository. It solves the problem of broken star-history.com embeds and automates tasks such as generating, updating, and embedding static star history charts directly in a repository’s README.md or other markdown files. The action provides features like a single self-contained binary with no external dependencies, adaptive y-axis ticks, and multi-repo comparison options to enhance visual representation of the chart.
July 18, 2026
Invigil — Product Quality Gate
Version updated for https://github.com/invigil/invigil to version v1.3.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that checks the product-quality of an open-source project against a specified doctrine. It ensures that projects are easy to use and boot in 10 minutes, provide actionable error messages, and verify published artifacts through daily machine verification. Invigil grades projects based on seven Gates (G1-G7) representing different levels of legibility and user experience, providing clear feedback for developers and ensuring the project is accessible to a wide range of users.
July 18, 2026
jk-neospec
Version updated for https://github.com/jedi-knights/neospec to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, runs tests in isolated environments, instruments Lua coverage via debug.sethook, and generates reports in LCOV, Cobertura XML, JUnit XML, and color console summary formats.
July 18, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a real-time guardrail that blocks AI coding agents from accidentally exposing secrets, such as reading .env files or writing secret-like values. It uses gitleaks for detection and provides shell scripts for integration into the agent’s tool boundary. The action helps prevent leaks before they occur by blocking sensitive file access and providing defense in depth with commit/CI scanning.
July 18, 2026
slopscore-lint
Version updated for https://github.com/jman4162/slopscore to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary slopscore is an AI-slop linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify and fix these patterns, nudging writers toward clearer and more specific prose.
July 18, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.93.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the unified AI integration platform that unifies 30+ AI providers and models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application with features like multi-provider failover, intelligent routing, and edge-first execution for cost optimization.
July 18, 2026
SupaPulse — Supabase keep-alive
Version updated for https://github.com/Karanjoshi128/supapulse to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action SupaPulse keeps a Supabase free-tier project from pausing by proving each ping actually reached Postgres, sending a random nonce with the ping and expecting it to be echoed back within two timestamps. If the check fails, it exits non-zero, triggering a red run in GitHub Actions that emails the user about the failure. The action also warns users about expiring anon keys and public repositories being disabled by GitHub.
July 18, 2026
HoverStare
Version updated for https://github.com/liuchong/hoverstare to version v0.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review bot that reads a GitHub repository like a human reviewer would. It uses Rust and runs as a single static binary as a GitHub Action. HoverStare reviews PRs incrementally, validates inline comments against the real diff, and tracks findings across commits until they are fixed. It also provides multi-pass voting and a verifier to ensure high signal and low noise in its findings.
July 18, 2026
Auth Route Guard
Version updated for https://github.com/mateuszingano/airlock-auth to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Auth Route Guard is a GitHub Action that scans Next.js projects to prevent server secrets from being exposed and provides warnings on unauthenticated mutations and webhooks. It flags potential security issues by checking NEXT_PUBLIC_* variables, mutating route handlers without auth checks, and webhook routes without signature verification. The action ensures build failure for critical findings and provides warnings for further review.
July 18, 2026
move-test-gen coverage check
Version updated for https://github.com/mehvetero/move-test-gen to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Move Test Gen is a GitHub Action that generates comprehensive edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic considerations. It automates the creation of #[test] and #[expected_failure] functions to ensure robust testing of Move contracts. The tool outputs a .move file targeting sui move test, making it easy to verify that tests are complete and compile correctly.
July 18, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that helps developers maintain project rules and lessons by using plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules. It provides a deterministic zero-LLM linter to enforce these rules, ensuring that architectural mistakes are caught before they become problems.
July 18, 2026
Agent Done Or Not
Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, agent-done-or-not, ensures that AI coding agents verify tasks before declaring success. It captures every check with a tamper-evident receipt (command + exit code + SHA-256 hash of the output) and blocks the agent from finishing until the most recent check is fresh and passing.
July 18, 2026
Star History Action
Version updated for https://github.com/narayann7/star-history-action to version v1.0.4.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Star History Action automates the process of displaying a self-updating star history chart in your own repository’s README. It solves the problem of rendering star-history.com badges on restricted endpoints and provides an alternative method using GitHub Actions and Node.js to render charts based on your own access token. The action runs in your CI, commits the rendered chart into your repo, and updates the README with a static image, ensuring that it only refreshes when there are actual changes to the stargazers data.
July 18, 2026
Changelog Bot Runner Nyaomaru
Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @nyaomaru/changelog-bot GitHub Action automates the creation of a polished changelog entry based on commit history, release notes, and optionally uses AI to generate summaries. It provides automated storytelling capabilities, can open PRs with the updated changelog, handles duplicate versions safely, and works as a CI-native action or reusable workflow.
July 18, 2026
phi.ag - Setup Binaryen
Version updated for https://github.com/phi-ag/setup-binaryen to version v1.0.10.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The phi-ag/setup-binaryen GitHub Action sets up the Binaryen toolchain, which is a compiler for WebAssembly. It automates the process of downloading and configuring Binaryen to streamline development workflows related to WebAssembly compilation and optimization tasks. The action supports specifying a specific version of Binaryen if needed.
July 18, 2026
Postman Onboarding AWS Spec Discovery
Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using only the existing AWS credentials. It helps in creating a source-of-truth specification for Postman onboarding, which can be used to generate deterministic collections, OpenAPI-backed contract checks, smoke tests, mocks, monitors, repo artifacts, and CI runs. The action supports various AWS providers, including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and uses IAM permissions for authorization.
July 18, 2026
memi design CI
Version updated for https://github.com/sarveshsea/memi to version v2.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: memi is a CLI tool that automates design QA for coding agents. It audits real interfaces, remembers design systems, and prevents UI regressions before merge. The action provides features like finding accessibility issues, loading design-system context, enforcing design CI checks, building SwiftUI interfaces, and generating compact briefs.
July 18, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.50.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security scans for AI agents, providing a fully offline and deterministic solution to identify misconfigurations, hardcoded secrets, tool poisoning, and other threats. It produces auditor-ready evidence packs in SARIF format and PDF reports mapped to 13 frameworks, ensuring compliance with EU AI Act, SOC 2, ISO standards, and regional regulations.
July 18, 2026
Argus PR Review
Version updated for https://github.com/sibinms/argus to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI PR reviewer that uses multiple narrow lenses to suggest potential issues and one curator to decide which ones are real. It automates the detection of bugs and security vulnerabilities in pull requests by analyzing them with various models from Anthropic, OpenAI, or other providers. The action integrates seamlessly into GitHub workflows for automated review without requiring separate configuration steps after initial setup.
July 18, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.4.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a GitHub Action and CLI tool that automates AI code reviews across various code hosts. It loads configuration from .pipr/config.ts, builds a deterministic Diff Manifest, runs Pi for structured output, validates findings against commentable ranges, and publishes Main Review Comments and capped Inline Review Comments. Supported delivery targets include GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud. The runtime owns diff modeling, Pi execution, structured output validation, stale-head checks, and comment publishing.
July 18, 2026
Graveyard Check
Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check is a GitHub Action that helps identify and recommend replacements for abandoned or at-risk dependencies in various ecosystems, such as npm, PyPI, and Go modules. It scans project lockfiles to determine if packages have been deprecated or not updated in a while, and suggests suitable alternatives. The tool supports multiple lockfile formats and can be used as a CI gate to ensure that only maintained versions are used.
July 18, 2026
Keep Node Current
Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action keeps Node.js versions in sync across repositories by fetching the latest release schedule and adjusting CI configurations, .nvmrc, and package.json files to reflect active LTS majors. It automates the process of updating matrices, single-version pins, and engine version declarations, ensuring compatibility with the official Node.js release schedule.
July 18, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.2.
This action is used across all versions by 137 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a configuration management tool, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions from lock files, with options for checksum verification and cache behavior control.
July 18, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.718.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action @vibgrate/cli is designed to analyze local codebases, providing insights such as a deterministic code graph and a drift score. It automates tasks like generating drift scores, building code graphs, and answering questions about the codebase. The action runs locally on the user’s machine without requiring any API keys or network connections, focusing on improving productivity for AI coding agents by offering local intelligence and documentation tools.
July 18, 2026
Symfony Security Auditor
Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.16.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered security auditor designed for Symfony applications. It uses multi-agent techniques to identify application-level flaws that traditional static analysis tools (PHPStan, Psalm) miss. The Auditor runs alongside other SAST tools and dependency scanners to provide a comprehensive security audit experience. The auditor can be used standalone as a CLI tool or integrated into a Symfony app via a bundle.
July 18, 2026
hide-comment
Version updated for https://github.com/int128/hide-comment-action to version v1.66.0.
This action is used across all versions by 231 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action hides (minimizes) comments in a pull request, providing flexibility through various filtering conditions and allowing the user to hide comments by issue number or GitHub token.
What’s Changed uses: int128/hide-comment-action@8cd375395d4b1630f8b70d17b802501a15d32561 # v1.66.0 What’s Changed chore(deps): update dependency @biomejs/biome to v2.5.2 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1651 chore(deps): update int128/release-typescript-action action to v1.75.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1653 chore(deps): update int128/update-generated-files-action action to v2.100.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1654 chore(deps): update int128/wait-for-workflows-action action to v1.86.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1655 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1656 chore(deps): update int128/update-generated-files-action action to v2.101.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1657 chore(deps): update pnpm to v11.10.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1658 chore(deps): update dependency @types/node to v24.13.3 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1660 chore(deps): update dependency @biomejs/biome to v2.5.3 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1659 chore(deps): update dependency vitest to v4.1.10 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1661 chore(deps): update pnpm to v11.11.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1662 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1664 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.65.0...v1.66.0
July 18, 2026
Official Junie GitHub Action
Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates JetBrains’ AI coding agent Junie into your workflows to automate code changes, issue resolution, PR management, and inline reviews. It helps developers interactively with their codebase through comments in issues, PRs, and CI/CD pipelines.
July 18, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that provides deterministic, offline linting and a queryable knowledge index derived from plain markdown lessons. It keeps project rules and context in the repository itself, ensuring architectural integrity survives PRs.
July 18, 2026
Agent Done Or Not
Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-done-or-not action ensures that an AI code agent doesn’t declare a task as complete without running checks first. It records each check’s evidence (command, exit code, and SHA-256 hash) and blocks the agent from finishing until it has a fresh, passing check. This helps prevent agents from making false claims of completion and ensures that tasks are completed reliably.
July 18, 2026
Aether Deploy
Version updated for https://github.com/Monoradioactivo/aetherpush-deploy-action to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of releasing React Native over-the-air updates using the Aether platform. It wraps the @aetherpush/cli release commands, providing features like deployment to different platforms and targeting specific binary versions. The action supports both release and release-react commands, handling various inputs such as app name, command, rollout percentage, and more, while outputting relevant metadata for further integration into CI workflows.
July 18, 2026
Kaniscope AI Code Review
Version updated for https://github.com/nhatvu148/kaniscope-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Kaniscope, automates AI code reviews by using an OpenRouter model to generate comments on pull requests. It posts line-anchored inline reviews and a summary comment, helping developers identify issues without blocking merges or edits. The action runs on a small Docker container and is cost-effective due to its integration with OpenRouter, which uses models like moonshotai/kimi-k2-0905 for cheaper reviews.
July 18, 2026
Quick OCP
Version updated for https://github.com/palmsoftware/quick-ocp to version v1.0.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action uses OpenShift Local to quickly deploy an OCP (OpenShift Container Platform) cluster on a GitHub Actions runner. It supports specific versions and configurations, including memory allocation, disk size, and operator readiness checks. The action also includes connectivity requirements and options for preloading images into the cluster registry.
July 18, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and scripts, and running tests. It helps ensure that the project is compliant with standards and practices by linking to Postman Insights and enforcing contract assertions through built-in smoke and contract runs.
July 18, 2026
Postman Onboarding AWS Spec Discovery
Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specs from AWS services using your existing AWS credentials. It solves the problem of setting up a source-of-truth spec hub for Postman onboarding by automatically detecting providers, resolving specs if they exist locally, and exporting them to Postman. The action supports various AWS services like API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and can be used in a CI/CD workflow without requiring GitHub tokens.
July 18, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.9.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action creates a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It automates the process of setting up a comprehensive test suite using RFC-based assertions and supports various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action provides executable contract tests and enforces adherence to industry standards.
July 18, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository and setting up CI, mock servers, and monitors. It helps streamline the setup of API development environments by integrating with Postman’s APIs and GitHub actions to manage configurations efficiently. The action supports various inputs for customizing the sync process, including workspace IDs, collection IDs, environment settings, and more.
July 18, 2026
Pipeline Pling
Version updated for https://github.com/Qbox-project/pipeline-pling to version v1.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipeline Pling is an action that automates the creation of readable Discord notifications from GitHub pushes, providing features such as customizable appearance, branch filtering, privacy controls, and retry mechanisms. It integrates with Discord’s webhook system to deliver push notifications directly to a specified channel.
July 18, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.34.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of validating and comparing new machine learning methods against existing codebases. It schedules runs weekly or allows for ad-hoc dispatches based on user inputs, providing self-review notes, issues, and a selection narrative in the step summary. The action uses pluggable model backends like Anthropic Opus and z.ai GLM-5.2 to evaluate candidates, with options for branch-only mode and cost considerations.
July 18, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.35.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
rumdl is a high-performance Markdown linter and formatter built in Rust. It aims to improve the linting experience by offering speed, numerous lint rules covering common Markdown issues, automatic formatting with fixable violations, zero dependencies, highly configurable via TOML, support for multiple Markdown flavors, and various installation options for different platforms including Rust, Python, npm, pip, uv, mise, Nix, Termux User Repository (TUR), Arch Linux, and standalone binaries.
July 18, 2026
ForgeProof Verify
Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of ForgeProof .rpack bundles in pull requests. It checks that the bundle’s root digest, signature, provenance chain, and all recorded artifacts are intact, ensuring AI-generated code remains secure. The action posts a human-readable audit report as a PR comment if enabled, and fails the check on tampering or missing evidence.
July 18, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.59.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes a Nix-based repository by automating several key tasks such as setting up Git user configurations, installing Nix from a cache, and applying configuration settings from a flake. It also provides options for creating a GitHub App token and using caching with niks3. The action runs efficiently in less than one minute and works across self-hosted and managed runners like GitHub Actions, Gitea, and Forgejo.
July 18, 2026
GitGalaxy Scanner
Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitGalaxy is a tool that provides a comprehensive macro-level view of software architectures across the entire repository. It automates the process of understanding the network dependencies and identifying local folder constraints, mapping out the exact flow of information across different languages and tasks. This allows for more efficient DevSecOps operations by providing detailed insights into codebase risks.
July 18, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.10.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw GitHub Action is a tool designed for managing Go monorepos by automating tasks such as generating and maintaining a unified go.work file, ensuring consistent dependency versions across modules, running commands in each module, and linting dependencies. It helps streamline the workflow of multi-module Go projects, reducing manual effort and improving collaboration among developers.
July 18, 2026
BlissOS-vm
Version updated for https://github.com/vmactions/blissos-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and execution of continuous integration (CI) workflows on BlissOS, a high-performance Android device OS. It simplifies the process of building and testing applications on BlissOS by handling the complex configuration and setup required to run CI in BlissOS environments. The action supports multiple releases and architectures and can be used with different sync methods to share code between the host and VM.
July 18, 2026
GhostBSD-vm
Version updated for https://github.com/vmactions/ghostbsd-vm to version v1.0.2.
This action is used across all versions by 27 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/ghostbsd-vm enables running CI in GhostBSD, a popular BSD distribution. It automates the process of setting up and managing virtual machines for testing or deployment tasks specific to GhostBSD. The action allows users to run commands and tests within a GhostBSD environment, with options to share files via rsync, sshfs, nfs, or scp, sync working directories, and more.
July 18, 2026
Haiku-vm
Version updated for https://github.com/vmactions/haiku-vm to version v1.1.3.
This action is used across all versions by 52 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a CI environment on Haiku, providing features such as AI-based workflow creation, automatic selection of compatible releases and architectures, SSHFS, NFS, or SCP code synchronization, and NAT port forwarding between the host runner and the VM. It simplifies the process of running tests and building projects on Haiku by handling many common setup tasks automatically.
July 18, 2026
MidnightBSD-vm
Version updated for https://github.com/vmactions/midnightbsd-vm to version v1.0.4.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/midnightbsd-vm is designed to run CI on MidnightBSD. It automates the setup and execution of tests on this popular BSD distribution by managing the environment, copying files, and running commands within a VM. The action supports various releases and architectures, including x86_64, and can be configured to use different synchronization methods like rsync, sshfs, or nfs. It also allows for passing environment variables and customizing the shell used during execution.
July 18, 2026
OpenIndiana-vm
Version updated for https://github.com/vmactions/openindiana-vm to version v1.1.4.
This action is used across all versions by 61 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, vmactions/openindiana-vm, automates CI testing on OpenIndiana systems. It allows users to run their CI workflows in an OpenIndiana virtual machine and is particularly useful for ensuring compatibility with 64-bit x86_64 architecture environments. The action supports various release versions of OpenIndiana, including fresh and build environments, and includes features such as environment variable forwarding, command execution, file synchronization, and directory mounting to facilitate seamless CI testing across different OSes.
July 18, 2026
Tribblix-vm
Version updated for https://github.com/vmactions/tribblix-vm to version v1.0.3.
This action is used across all versions by 27 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Run GitHub CI in Tribblix action is designed to enable running CI workflows on the Tribblix operating system. It provides an AI-ready feature that automatically generates the necessary GitHub Actions YAML configuration based on user input, handling tasks such as setting up toolchains, installing dependencies, and managing environment variables. Key capabilities include support for various VM releases, different architectures, and methods of code synchronization (e.g., rsync, sshfs, nfs). The action simplifies the process of setting up CI pipelines in Tribblix by automating common setup tasks and reducing the need to manually configure each pipeline.
July 18, 2026
Legion Runner
Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.42.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action that secures GitHub Actions by monitoring and blocking outbound connections based on allowlists. It records processes associated with outbound traffic and detects file tampering during job execution. The Action runs locally without dependencies and can be used to enhance the security of CI pipelines.
July 18, 2026
Sparda MCP
Version updated for https://github.com/zyx77550/sparda to version v0.63.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a compiler that transforms backend behaviors into an abstract, mathematical graph. It helps ensure that all tools (linters, debuggers, deploy gates) can reason about the application’s behavior at compile time, improving efficiency and reducing runtime dependencies. With SPARDA, developers can verify, prove, and execute their applications without exposing them to AI agents or external APIs.
July 17, 2026
SDD Validate
Version updated for https://github.com/juanklagos/spec-driven-development-template to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Spec-Driven Development Template is a practical approach to software development using AI agents. It helps teams plan and validate their projects by writing clear specifications before code creation, ensuring that decisions are documented and traceable. The action automates tasks such as validating spec structures and enforcing rules through an enforcement script. The template provides educational resources for both non-technical founders and technical developers, offering a unified workflow for applying SDD in real projects.
July 17, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.92.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that simplifies the process of integrating various AI providers into applications. It provides a consistent API across 30+ models and supports a wide range of tools and modalities like text-to-speech, image generation, and music creation. The action automates tasks such as stream processing and intelligent routing, making it easier to integrate AI into various applications efficiently.
July 17, 2026
setup-jemalloc
Version updated for https://github.com/kaeawc/setup-jemalloc to version v0.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads and installs jemalloc, which replaces the default malloc to free up memory left unusable by fragmentation. It supports Linux platforms but requires building with arm64e architecture for macOS and is not supported on Windows. The action ensures atomic installation and idempotence, allowing it to be safely invoked multiple times within a job without interference.
July 17, 2026
Kusari Ingest
Version updated for https://github.com/kusaridev/kusari-ingest to version v4.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The kusari-ingest GitHub Action automates the process of ingesting various artifacts (SBOMs, SLSA attestations) into the Kusari Platform. This action simplifies the integration with Kusari by handling authentication credentials and providing options to generate an SBOM from source or a container image. The action also captures ingestion results and automatically maps components if required, enhancing ease of use for developers and DevOps teams in integrating automated security measures within their workflows.
July 17, 2026
OctoSTS
Version updated for https://github.com/launchdarkly/octosts-action to version v1.4.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README facilitates the exchange of a workflow’s identity token for a GitHub token using an OctoSTS service. It automates the process of federating a GitHub repository with a trusted third-party, providing a secure and seamless authentication mechanism without the need to manually generate or manage tokens. This action simplifies the integration of external services into GitHub workflows by automatically managing access permissions based on configured trust policies.
July 17, 2026
E2E Self-Heal
Version updated for https://github.com/Lee-Dongwook/E2E-Self-Heal to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A self-healing engine that uses AI to automatically repair broken Playwright E2E tests by diagnosing and patching failing selectors, ensuring tests remain resilient to UI changes. The tool can operate in two modes: auto-heal (re-running the test until it passes) or review (diagnosing why a selector broke and suggesting source-level fixes as inline PR comments). It resolves selectors against the live DOM and checks if each patch resolves to exactly one element before running the test again.
July 17, 2026
Lingo.Dev AI Localization
Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.2.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lingo GitHub Action automates the continuous localization of text across repositories using the Lingo.dev platform. It simplifies the process of translating content, ensuring consistent and high-quality translations with features like AI-assisted setup and integration with existing translation engines. This action streamlines the localization workflow by automatically handling changes in text files and ensures that only necessary updates are processed.
July 17, 2026
Blast Radius verify
Version updated for https://github.com/Lockelamoree/Blast_Radius to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Blast Radius is a browser-based game designed to help developers practice making safe approval decisions around AI code agents. It offers 20 pre-defined scenarios, a deterministic gate system, and the ability to track action outcomes and evidence with receipts. The application supports multiple browsers and can be run locally or hosted on a server.
July 17, 2026
tofu-garnish
Version updated for https://github.com/lowlydba/tofu-garnish to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action automates the process of publishing OpenTofu/Terraform outputs as a static HTML page on GitHub Pages. It provides a user-friendly interface to view and filter Tofu output data, with sensitive information masked automatically. The action is dependency-free, supports structure-aware HTML rendering, and can handle multiple workspaces or tenants efficiently.
July 17, 2026
Pipelock Agent Security Scan
Version updated for https://github.com/luckyPipewrench/pipelock to version v3.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipelock is an open-source AI-driven firewall designed to monitor and secure AI agents by inspecting mediated network traffic. It identifies potential threats such as secret exfiltration, prompt injection, and SSRF, emitting mediator-signed action receipts that third parties can verify outside the agent runtime. This helps ensure the integrity of data transmitted between AI agents and networks.
July 17, 2026
Airlock Migration Guard
Version updated for https://github.com/mateuszingano/airlock-migrate to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Migration Guard is a GitHub Action designed to prevent Supabase/Postgres migration scripts from introducing data leaks or breaking authentication by checking for certain conditions such as tables without RLS, disabled RLS, permissive policies, and dropped policies/triggers. It helps identify potential issues before they reach production, ensuring the integrity of the database schema and security measures are maintained.
July 17, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede is a free static analysis tool that automatically detects authorization bugs like IDOR, missing access controls, and privilege escalation. It performs cross-function analysis to trace data flow from HTTP routes to database queries or other sensitive sinks without relying on network connections or API keys. Ansede is designed to catch these security flaws before attackers do, offering a 100% CVE recall rate across multiple programming languages.
July 17, 2026
GHGen Workflow Analyzer
Version updated for https://github.com/nigelhorne/App-GHGen to version v6.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GHGen Workflow Analyzer is a GitHub Action that automates the process of generating, analyzing, and optimizing CI workflows. It automatically detects project types and generates workflows with caching, security, concurrency, and best practices built-in. It also analyzes existing workflows for performance bottlenecks, outdated actions, missing security permissions, and wasted CI minutes, and applies safe, intelligent fixes or opens a clean pull request with improvements.
July 17, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.18.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Apex unit tests and executing anonymous Apex code locally without needing an org or sandbox environment. It provides local execution of SOQL, DML, and test data, supports triggers, validation rules, flows, governor limits, and the standard library, with a focus on behavior similar to Salesforce’s Apex runtime. The action can be used in CI/CD pipelines for continuous testing and development.
July 17, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.35.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: Prowler is an Open Source Cloud Security Platform designed to automate security and compliance in any cloud environment. It offers a wide range of security checks, remediation guides, and compliance frameworks to help organizations ensure their cloud resources are secure and compliant.
July 17, 2026
Generate Roq Site
Version updated for https://github.com/quarkiverse/quarkus-roq to version 2.1.6.
This action is used across all versions by 77 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Roq is a free static site generator built with Java and Quarkus that simplifies the process of creating websites and blogs. It automatically generates HTML files from templates and articles, and offers extensions like Roq Data and Roq FrontMatter for enhanced content management. The GitHub Action integration allows users to deploy their sites directly through Actions, while standalone usage provides flexibility for developers who want to use Quarkus Roq’s features without additional setup.
July 17, 2026
latexindent-action
Version updated for https://github.com/quentin-rodriguez/latexindent-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LaTeXindent-action is a GitHub Action that checks or applies latexindent formatting on .tex files, using a custom configuration file and additional options. It provides flexibility in configuring the action via a YAML file and allows passing extra arguments to latexindent. The summary explains its purpose, functionality, and how it solves problems related to LaTeX formatting automation in GitHub workflows.
July 17, 2026
setup-openapi
Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a workflow for generating OpenAPI clients using the OpenAPI Generator CLI. It installs Java, caches the CLI by version, and exposes the binary for use in subsequent steps in a GitHub Actions workflow. The action is designed to help developers quickly set up their workflows to generate code from OpenAPI specifications.
July 17, 2026
Publish APKs to esper.io
Version updated for https://github.com/ryanoboril/action-esper.io-upload-multi to version 2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading one or more APK files to esper.io using their API. It requires specifying the Esper.io Enterprise ID, API Key, and tenant name, along with the folder containing APK files to upload. The action also allows for optional release comments to be applied to each uploaded APK version. The result data from the upload operation is available as an output.
July 17, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code-owned AI review action that automates structured, provider-neutral reviews across popular code hosts (GitHub, GitLab.com, Azure DevOps Services, and Bitbucket Cloud). It uses a TypeScript configuration file to define review workflows and integrates with various code hosting providers through adapters. The tool runs AI-driven reviews, validates findings, and publishes comments in GitHub pull requests.
July 17, 2026
runward gate
Version updated for https://github.com/stranxik/runward to version v0.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an agent delivery framework that automates the entire mission from framing to handover, addressing architecture problems in agentic systems by providing structured delivery and governance. It supports various input sources like specs, OpenSpecs, and prototypes and offers six gated phases: Frame, Spec Kit, OpenSpec, Brownfield, Floor, Evolution on Evidence, Governance, and Handover. Runward ensures that agentic systems are built, tested, and delivered with resilience and autonomy, making them robust against unpredictable outputs and complex environments.
July 17, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.1.
This action is used across all versions by 137 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a dependency manager for Rust projects, in your GitHub Actions workflow. It allows users to install specific versions of Tombi or resolve dependencies from lock files, and it provides options for caching the installation for faster future runs. The action supports various checksum verification methods for ensuring the integrity of downloaded binaries.
July 17, 2026
Setup Upwarden
Version updated for https://github.com/upwarden-io/setup-upwarden to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-upwarden action provides a simple and secure way to authenticate and attribute package manager dependencies in CI pipelines. It uses the user’s OIDC identity to mint a short-lived token, ensuring that each dependency fetch is authenticated and attributed, and can be policy-enforced. The action is highly configurable with options for different ecosystems (npm, pip, maven) and supports both GitHub and non-GitHub environments.
July 17, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v3.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a Rust-based linter designed to validate various configurations related to Claude Code, Cursor, and Codex. It checks for compliance with specific lint rules across multiple categories such as Manifest, Hooks, Skills, Agents, Prompt Content, Claude Rules, Output Styles, Settings, Hygiene, Email, User Config, MCP, Codex, Slack, Docs, Markdown Structure, Link/import integrity, and more. The action supports both Basic mode (for standard configuration validation) and Plugin mode (which runs the full rule suite when a .claude-plugin/ directory is present). Agent Lint is configurable through agent-lint.toml to suppress or downgrade rules. It offers integration options via GitHub Actions and pre-commit, with cross-platform binaries available for macOS, Linux x86_64/aarch64, and macOS aarch64.
July 17, 2026
Sparda MCP
Version updated for https://github.com/zyx77550/sparda to version v0.58.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles backend behavior into a graph, enabling tools to reason about and verify applications. It helps in identifying and fixing issues by compiling routes, database queries, and state mutations into a single, language-agnostic graph, which can then be verified and replayed without running the actual application.
July 17, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild action automates the setup of CI/CD pipelines for iOS and Android projects on GitHub. It provides interactive and non-interactive setup options, including auto-detection of platform and project type. The action generates a YAML-based pipeline with recommended defaults or allows users to customize it using an interactive wizard. Users can run the generated pipeline locally or remotely after validation. It supports adding secrets for environment variables and key management, and provides utilities for uploading secrets to GitHub environments.
July 17, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a deterministic guardrail designed to prevent AI coding agents from accidentally exposing sensitive information, such as .env files containing private keys or credentials. It monitors the agent’s interactions with these files at runtime and blocks them if they attempt to read or write sensitive data before it can be used. This tool helps in real-time detection of potential leaks by using gitleaks for scanning and plain shell scripts for integration, ensuring defense-in-depth security measures are implemented.
July 17, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.92.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a unified API to integrate 30+ AI providers and models. It offers features like switching providers with a single parameter change, leveraging built-in tools, deploying with enterprise features, optimizing costs automatically, and using the professional CLI or TypeScript SDK. The platform supports edge-first execution and continuous streaming architectures for practical and universally available AI.
July 17, 2026
Threatify Scan
Version updated for https://github.com/kamranhasan/Threatify to version 0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Threatify is a static analysis tool that generates a capability graph from an AI agent’s configuration and identifies potential attack paths. It helps in detecting hidden vulnerabilities such as LETHAL_TRIFECTA and ATTACK_PATHs, which can be used for exfiltration or unauthorized access. The tool runs offline, analyzing the configuration file alone without relying on external APIs or network calls.
July 17, 2026
Lint package.json
Version updated for https://github.com/kirkeaton/action-publint to version v2.0.20.
This action is used across all versions by 13 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action action-publint automates the linting of a package.json file to detect packaging errors using Publint. It helps identify issues related to dependencies, metadata, and version management that could affect how your project is published. The action provides flexibility in setting the logging level and the path to the package directory for custom configurations.
July 17, 2026
Landsafe — Postgres migration safety
Version updated for https://github.com/landsafe-dev/action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Landsafe GitHub Action checks PostgreSQL migration safety by analyzing the diff between two database schemas and identifying potential issues such as blocking index builds, full-table rewrites, and data loss. The action verifies these risks without connecting to or interacting with the actual database, ensuring that developers are aware of potential production impacts before merging migrations.
July 17, 2026
Git Velocity Analyser
Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.12.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your Git repositories and generates a gamified dashboard showing developer velocity metrics. It helps track contributions, automates code review processes, and provides achievements to motivate team members in their development efforts.
July 17, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.12.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The lgtmaybe GitHub Action reviews pull requests by analyzing code changes and surrounding lines from the file, detecting logic and correctness bugs, security vulnerabilities, missing or weak tests, outdated code, performance regressions, unnecessary complexity, intent, and ponytail. It uses a language model to generate inline review comments and summaries, reducing the need for static keys and improving safety.
July 17, 2026
Code Guard PR Scanner
Version updated for https://github.com/mlawsonking/code-guard-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action mlawsonking/code-guard-action scans code changes in pull requests for security bugs using a deterministic rule engine, flagging them inline on the diff and posting findings as annotations. It automates the process of catching high-frequency vulnerabilities such as command injection, SQL injection, SSRF, hardcoded secrets/API keys, weak crypto, unsafe deserialization, disabled TLS verification, and XSS. The action runs on added lines in each PR, checks them with a deterministic rule engine, and posts findings inline on the “Files changed” tab. It can be configured to fail the check based on the worst verdict level or not at all.
July 17, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.100.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that integrates AI coding agents, provides a queryable knowledge index, and enforces lint rules to maintain architectural integrity in projects. It uses deterministic zero-LLM linting and avoids network calls by storing lessons and lint configurations locally.
July 17, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action designed to audit and consolidate AGENTS.md, CLAUDE.md, and related harness files in repositories. It helps developers identify and correct inconsistencies, ensuring that the agent’s documentation remains accurate, up-to-date, and secure. The tool also measures whether the resulting harness improves agent answers by comparing before- and after-performance metrics.
July 17, 2026
Zablo — zero-knowledge secrets
Version updated for https://github.com/r2l332/zablo-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action fetches zero-knowledge secrets from a Zablo server and injects them into your GitHub Actions workflow using an OIDC token, without storing any sensitive information in public repositories. It supports both static API keys and OIDC federation methods to access the secrets securely. The action is designed for use with workflows that require deployment or configuration tasks that involve sensitive data like database URLs, Stripe keys, and Redis passwords.
July 17, 2026
raviqqe/muffy
Version updated for https://github.com/raviqqe/muffy to version v0.3.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Muffy GitHub Action automates the process of validating static websites by running Muffet, a static website validator. It solves the problem of checking website validity and provides key capabilities for ensuring that HTML and CSS are correctly formatted and that links work as expected.
July 17, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.33.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Outrider, automates the process of validating and comparing new methods against an organization’s existing codebase. It uses Anthropic Opus or z.ai GLM-5.2 as model backends to evaluate arXiv methods (or design-doc leads) against real call sites, providing a self-review and issue routing feature. It supports branch-only mode and avoids duplicate work by not re-recommending papers once they have been referenced. The action is designed to streamline the integration of new models into production environments while ensuring compliance with code review metrics.
July 17, 2026
RabbitMQ Publish
Version updated for https://github.com/rikkaneko/rabbitmq-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The RabbitMQ Publish Action automates the process of publishing UTF-8 payloads to a RabbitMQ or AMQP exchange or queue using GitHub Actions. It supports both username/password and mTLS certificate authentication, as well as newline-separated key=value AMQP headers and optional consumer acknowledgement through RabbitMQ direct reply-to. The action is configured via inputs and requires secrets for sensitive data storage.
July 17, 2026
ForgeProof Verify
Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of ForgeProof .rpack bundles in pull requests. It ensures that AI-generated code is properly sealed into provenance bundles and checks their integrity and completeness, failing the check on tampering. The action posts a human-readable audit report as a PR comment and writes the same report to the job summary. It supports glob patterns for bundle paths and options to control strictness and require bundle presence.
July 17, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.7.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates a crew of CLI coding agents to execute tasks in parallel against a single goal using deterministic scheduling. It provides an HMAC-signed audit chain with bearer-token authentication, signed agent cards, and per-artefact lineage recording.
July 17, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.52.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Console-CensorChecker is a PowerShell-based tcping batch probing and review detection script for checking network censorship status. It provides tools to check Tcping latency and service availability, with options to automate tasks through PowerShell scripts, modules, or GitHub Actions. The tool is suitable for any platform and can be used to monitor and review network services without bypassing censorship devices.
July 17, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw GitHub Action automates and simplifies working with Go workspaces by generating, maintaining, and linting dependencies across multiple modules. It allows users to run commands, sync dependencies, check linting issues, and manage module configurations efficiently. The action handles tasks like moving replace directives, syncing use sets, and verifying release contracts in a multi-module environment.
July 17, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.715.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, @vibgrate/cli, automates local codebase intelligence and analysis tasks for AI coding agents. It provides a deterministic code graph with call trees, import paths, impact surfaces, dependency facts, and a drift score to assess how far behind the codebase is from current standards and best practices. The action runs on your machine without relying on external APIs or network calls, ensuring no data leaves your repository unless explicitly pushed.
July 17, 2026
Derive Ruby versions
Version updated for https://github.com/voxpupuli/ruby-version to version 2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Ruby version determination GitHub Action reads a gemspec to determine the compatible Ruby versions for your testing matrix. It provides an output of compatible versions that can be used in CI pipelines to automate the process of setting up Ruby environments based on the specified requirements. The action supports Ruby versions from 2.4 to 4.0 and maintains a static list of compatible versions.
July 17, 2026
WAF++ PASS Scan
Version updated for https://github.com/WAF2p/wafpass-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The WAF++ PASS GitHub Action automates the execution of WAF++ scans on IaC files in a repository and pushes the results to a specified WAF++ server endpoint. It supports various IaC frameworks like Terraform, Bicep, CDK, and Pulumi. The action handles both bearer token and API key authentication for secure communication with the server. It also provides output parameters such as run_id, score, and findings_count to help users track the scan’s status and results.
July 17, 2026
Feishu Notification
Version updated for https://github.com/Waybox-AI/feishu-notification to version v1.0.21.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends interactive card notifications to a Feishu (Lark) group chat when pull request events occur in your repository, providing notifications on PR opened, new commits pushed, and merged into the main branch. It skips closed PRs or those not merged into main.
July 17, 2026
Kimi Code Action
Version updated for https://github.com/xuwenhao/kimi-code-action to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates code review and implementation tasks in pull requests and issues using the kimi-code CLI. It detects which mode to run based on events like comments or mentions of @kimi. Features include automatic mode detection, interactive code assistance, code review, code implementation, progress tracking, commit signing, session resume, and security hardening. The action runs entirely on GitHub runners with minimal external calls.
July 17, 2026
Kover Report Action
Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports various discovery methods and customizable thresholds, enabling easy integration into CI/CD workflows. The action also provides automatic PR comments for coverage results with trend indicators and allows exporting coverage data for further use.
July 17, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v2.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a versatile linter for Claude Code, Cursor, and Codex configurations. It checks for various issues related to manifest files, hook paths, skill frontmatter, agent fields, prompt content, Claude rules, output styles, settings, hygiene, email format, user configuration, MCP server setup, Codex configuration, Cursor rules, and Cursor skills. The tool supports both Basic and Plugin modes based on the presence of .claude-plugin/ in the repository, and it provides a GitHub Action for easy integration into CI pipelines.
July 17, 2026
Draugr Security Scan
Version updated for https://github.com/draugr-dev/draugr to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Draugr, automates developer-first security scanning of applications. It uses a single descriptor file (draugr.saga.yaml) to declare software components and dependencies, enabling the orchestration of various security controls such as image scanning with Trivy, secret detection with Gitleaks, and source code analysis with Semgrep. Draugr normalizes results to SARIF format for easy integration into continuous integration pipelines, allowing developers to prioritize and gate scans based on criticality levels.
July 17, 2026
Semantic Version Release
Version updated for https://github.com/EasyDesk/action-semver-release to version v1.1.8.
This action is used across all versions by 67 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating major and minor version tags when a release is triggered, creating corresponding GitHub releases, and handling semantic versioning to ensure version consistency. It supports handling conditional execution based on version format, making it suitable for projects that require precise version management and tagging practices.
July 17, 2026
Pitwall k6 Report
Version updated for https://github.com/florin-stefan/pitwall-k6 to version 0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Pitwall-k6, automates the process of generating and serving a comprehensive HTML report from k6 load test results. It parses various output formats (raw JSON stream, summary files) to reconstruct detailed metrics including thresholds, checks, and pass/fail verdicts. The generated report includes charts for trends across runs and a glossary of key metrics. Users can easily serve the report locally or directly in their web applications, making it accessible without additional backend infrastructure.
July 17, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.509.
This action is used across all versions by 19 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the security, publishability, runtime readiness, and trust signal verification of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The default install path uses an exact PyPI release, verifies its provenance against hol-guard, and only then installs it. Advanced distribution paths are available when needed.
July 17, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.509.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It checks for security, publishability, runtime readiness, and trust signals, emitting structured reports, SARIF, policy results, and submission metadata. The action stays aligned to the main scanner release train and can be used in workflows by specifying paths and execution modes.
July 17, 2026
action-tag-release-build
Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.7.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “tag-release-build” automates the process of bumping the version number, creating a tag, updating a CHANGELOG, and optionally publishing a release in GitLab CI/CD pipelines. It uses semantic versioning based on commit messages to determine the type of update (major, minor, or patch). The action supports syncing the updated version with package.json files and Claude Code plugin files for easy integration into existing projects.
July 17, 2026
Agentic Workflow Guard
Version updated for https://github.com/jinyounghub/agentic-workflow-guard to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action agentic-workflow-guard is a static analyzer designed to detect and prevent AI-agent-specific vulnerabilities in GitHub Actions workflows. It focuses on identifying potential risks where untrusted event data, such as issue bodies, PR comments, branch names, or commit messages, are passed into AI agent prompts, potentially leading to write permissions, scripts, release commands, or secrets being executed with elevated privileges. This action helps ensure the security of CI/CD pipelines by monitoring for these high-risk patterns without requiring access to API keys or sending sensitive workflow content to external models.
July 17, 2026
setup-jemalloc
Version updated for https://github.com/kaeawc/setup-jemalloc to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads, installs, and caches jemalloc, replacing the default malloc to free up unused native memory due to fragmentation. It supports Linux but requires arm64e target architecture on macOS. The action can be invoked multiple times within a job without affecting existing processes, ensuring atomic installations and idempotency.
July 17, 2026
16 Eyes
Version updated for https://github.com/kigiela/16-eyes to version v1.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action is designed to perform security audits on code repositories using AI-driven tools. It provides a comprehensive, multi-agent approach to identify and verify security issues across an entire repository or specific changes in a pull request. The action profiles the repository’s architecture and design before automating the scanning process with tailored lenses that check for vulnerabilities, ensuring robust and skeptical review processes.
July 17, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary runner is an action designed to help developers quickly identify and run commands across multiple task runners and package managers within their projects. It provides a tab completion feature that suggests available tasks and packages, reducing the need to remember specific command structures or configurations for different repositories. This tool enhances efficiency by automating the process of selecting the correct runner and command for executing tasks, making it easier to manage and run project-related commands without manual configuration.
July 17, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.99.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a GitHub Action that enhances AI coding agents by providing a file-based toolkit. It helps prevent common mistakes and architectural issues by enforcing clear rules and lessons through plain text markdown files. The action includes a queryable knowledge index and a zero-LLM linter to ensure deterministic code, enhancing the integrity of project architecture and reducing the need for frequent re-explaining between sessions.
July 17, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is an automated tool designed to audit AI harnesses and provide insights into their consistency, security, and efficacy. It helps in consolidating scattered instructions into a single AGENTS.md file and ensuring that all related files are kept small pointers. The tool also measures the improvement in agent answers after consolidation.
July 17, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.17.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer GitHub Action runs Apex and unit tests locally without requiring an org or deployment. It supports running Apex code, executing anonymous code, stepping through Apex in an interactive debugger, and simulating Salesforce governor limits, standard library features, and testing framework capabilities.
July 17, 2026
pgrls — Postgres RLS linter
Version updated for https://github.com/pgrls/pgrls-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action pgrls-action automates the use of the static analyzer pgrls to detect and prevent Row-Level Security bugs in PostgreSQL databases. It supports two modes: linting a live database’s RLS state or serving as a pull-request gate that checks for regressions and new issues in schema changes without requiring a running database.
July 17, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace by importing an OpenAPI specification. It generates baseline, smoke, and contract collections with executable tests covering various protocols (OpenAPI, gRPC, SOAP, GraphQL, AsyncAPI, MCP). The action simplifies the setup process for new projects and integrates seamlessly with other Postman CI/CD actions.
July 17, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action exports Postman collections and environments into a repository and automates the setup of CI, mock servers, and monitors. It solves the problem of synchronizing Postman assets with code repositories and provides a seamless integration with workflows. The action supports various configurations such as workspace IDs, collection IDs, and environment details.
July 17, 2026
Oversight Lint
Version updated for https://github.com/rachelslurs/oversight-lint-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates linting of Storybook MCP components manifest files. It checks for missing or improperly documented components, surfaces warnings as annotations on pull requests, and exits with appropriate error codes based on rule violations or exceeding warning limits. It requires a built manifest, Node 20.19+, and supports customizable rules through an oversight.config.json file.
July 17, 2026
sbomify
Version updated for https://github.com/sbomify/sbomify-action to version v26.7.0.
This action is used across all versions by 26 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sbomify-action is designed to automate the creation, enrichment, and management of Software Bill of Materials (SBOMs) in CI/CD pipelines. It supports various ecosystems including Python, Node.js, Rust, Go, Ruby, Dart, C++, and Docker images, and can generate CycloneDX or SPDX SBOM formats. The action can also leverage Chainguard base images for efficient SBOM creation, enhancing the process with additional metadata from package registries.
July 17, 2026
Skill Provenance Validate
Version updated for https://github.com/snapsynapse/skill-provenance to version v5.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action ensures that agent skills across local folders, registries, and platform uploads maintain their integrity by recording version information and hash-based integrity verification inside the bundle. This helps teams verify version identity, detect staleness, and ensure no accidental drift during transitions.
July 17, 2026
Tenzai Test
Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates security testing of an existing Tenzai application after a deployment. It triggers a commit-diff test and posts results as a Tenzai Test check run on the tested commit, providing feedback directly within the repository workflow. The action is designed to be fire-and-forget, ensuring that tests are triggered asynchronously and providing real-time status updates.
July 17, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw is a Go tool designed to manage multi-module workspaces efficiently, automating common tasks such as bootstraping go.work, linting dependency versions, and running commands across modules. It helps developers maintain complex Go projects more effectively by streamlining the process of managing dependencies and automating repetitive tasks.
July 17, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.89.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The miu-cr GitHub Action automates AI-based code review for CLI, CI, and MCP hosts. It provides features like local review of staged changes, integration with GitHub PRs for inline comments, and support for custom project rules via .miu/cr/rules/*.md files. The action also offers CI/Actions integration through reusable workflows and supports evaluation using miucr eval.
July 17, 2026
Sync Issues and PRs
Version updated for https://github.com/vig-os/sync-issues-action to version v0.4.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, sync-issues-action, automates the process of syncing all issues and pull requests from a repository into markdown files. It captures all comments and conversations within each issue or PR, groups review threads with diff snippets when available, preserves original bodies without extra headers, and includes metadata such as labels, dates, authors, state, relationships, etc. The action supports various options for customization, including specifying output directories, filtering issues or pull requests, customizing the format command, and using GitHub App authentication. It also provides outputs for tracking sync results and managing state files for caching purposes.
July 17, 2026
Setup ZeroDrop
Version updated for https://github.com/zerodrop-dev/setup-zerodrop to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-zerodrop GitHub Action generates a unique inbox per CI run, allowing email verification and OTP extraction at Cloudflare’s edge. It solves the problem of managing isolated inboxes for parallel test runs and provides an easy way to integrate email verification into workflows using ZeroDrop SDKs.
July 17, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v2.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Agent Lint GitHub Action is a lint tool for validating Claude Code, Cursor, and Codex configurations. It implements a robust suite of 286 lint rules across 20 categories to ensure consistent and high-quality setup files. The action supports both Basic and Plugin modes and can be easily integrated into CI pipelines or used with pre-commit hooks.
July 16, 2026
BPFCompat eBPF Compatibility Gate
Version updated for https://github.com/Kernel-Guard/bpfcompat to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary bpfcompat is an open-source compatibility validator that tests eBPF artifacts across real distro kernels. It boots virtual machines, runs the artifact in those environments, and produces JSON/Markdown reports that indicate whether the artifact loads and attaches on the specified kernels. This allows for empirical validation of eBPF compatibility, unlike CO-RE which provides a portability guarantee but not necessarily a load-and-attach guarantee.
July 16, 2026
npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: npm-scan is an advanced tool designed to detect a wide range of supply chain attacks, including eBPF kernel rootkits, memory extraction, credential theft, GitHub spoofing, AI-targeted attacks, and more. It complements traditional tools like npm audit and Snyk by offering behavioral detection that can identify hidden threats.
July 16, 2026
Lingo.Dev AI Localization
Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.1.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Lingo.dev” automates the localization process by connecting to Lingo.dev’s translation platform. It enables continuous localization in GitHub Actions, reducing terminology errors and providing a structured approach to i18n setup, especially for React applications. The action supports various file formats like JSON, YAML, Markdown, CSV, and PO files, and it integrates with Lingo.dev’s API for seamless integration into development workflows.
July 16, 2026
Install Lua / LuaJIT / OpenResty + LuaRocks
Version updated for https://github.com/luau-project/setup-lua to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs Lua (or LuaJIT or OpenResty) and LuaRocks in a single step within the .lua folder, supporting various versions and configurations. It automates the setup process across different operating systems and toolchains, including MSVC on Windows. The action allows for customization of Lua and LuaRocks versions through inputs, providing options to skip LuaRocks installation or specify specific commit hashes for LuaJIT and OpenResty.
July 16, 2026
CSDA Version
Version updated for https://github.com/NASA-IMPACT/csda-version to version v0.4.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates and updates the CSDA version for the checked-out repository. It automates the process of determining the next version based on predefined rules and is particularly useful when integrating with tools like release-please to handle automated releases. The action ensures that the versioning follows a specific format (vYY.PI.SP-X) and can be customized by setting release-as and config-file in the with block of the Github Action YAML file.
July 16, 2026
StayAwakeBot Strix
Version updated for https://github.com/Ndevu12/strix to version v0.1.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Strix, automates the detection of self-propagating worm indicators in checked-out repositories by running a Python package called stayawakebot. It scans the repository and reports on any suspicious or infected targets, failing CI when necessary. The action is configured with various inputs for customization such as specifying a specific version of stayawakebot, including a configuration file, setting failure conditions, and controlling how findings are reported (e.g., through SARIF files, artifacts, or comments).
July 16, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.26.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a specified proxy cache whenever new releases are tagged in your Go module repository. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version. The action ensures that your module is immediately available on platforms like pkg.go.dev, making it simple to integrate into continuous integration workflows.
July 16, 2026
Open Delivery Spec
Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.3.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ODS Validate Action automates the AI code quality gate by attributing AI-generated code using Co-Authored-By trailers, analyzing code quality, scoring technical debt, and enforcing policy through OPA Rego. It runs on every pull request to prevent low-quality AI code from reaching production.
July 16, 2026
Minisign Release Signer
Version updated for https://github.com/pattonwebz/minisign-release-signer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the signing of release artifacts (like WordPress plugins and themes) with Minisign, a digital signature tool that uses Ed25519 keys. The action creates detached signatures, verifies them against a published public key, and logs each signature in Sigstore Rekor for transparency. It supports multiple files per release and provides replay protection by embedding trusted comments in the signatures. The action is designed to work seamlessly with WordPress workflows but can be used for any distributable artifact.
July 16, 2026
MegaLinter Custom Flavor PracticalliZensical
Version updated for https://github.com/practicalli/megalinter-custom-flavor-zensical to version Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-practicallizensical], unable to determine latest release.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This custom MegaLinter aims to reduce the Docker image size by removing unused linters and dependencies. It focuses on providing a lightweight and optimized version of the official MegaLinter images, suitable for use in GitHub Actions workflows and Docker environments. The action automatically keeps up to date with MegaLinter releases through scheduled builds and can be configured to publish to both GitHub Container Registry (ghcr.io) and Docker Hub.
July 16, 2026
ramen-ai PR Compliance Interceptor
Version updated for https://github.com/ramen-ai-dev/ramen-ai-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 22.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “ramen-ai PR Compliance Interceptor” is designed to block unsafe AI outputs before execution in pull requests. It scans pull request diffs, evaluates added text against the ramen-ai L2 Semantic Firewall, and fails the CI build on a [BLOCKED] verdict, posting a cryptographically-receipted comment on the PR.
July 16, 2026
Misata Seed Data Audit
Version updated for https://github.com/rasinmuhammed/misata-audit-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of seed data by running the misata audit tool on a specified directory of CSV files. It checks for various inconsistencies such as orders shipped before they were placed, ages not matching birth dates, cancelled orders with tracking numbers, negative counts, high fraud rates, and cross-table relationships like foreign-key orphans and causality issues. The action fails the CI job if any problems are found, and provides detailed logs indicating which tables, columns, and rows have issues. It supports schema validation to further enhance checks and can be run with zero tolerance for errors.
July 16, 2026
skill-switch audit
Version updated for https://github.com/rtwsvj/skill-switch to version v0.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans Claude Code, Cursor, Gemini CLI, Windsurf, Zed, and VSCode skills and configurations to detect potential security issues such as反弹 shell, exfiltration of sensitive files, phishing credential theft, dangerous MCP servers, plaintext remote transmission, hard-coded keys, among others. It provides SARIF output for easy integration into GitHub code scanning, supports project-level policies, and includes automated fixes (--fix).
July 16, 2026
pi GitHub Action
Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.26.0.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates the Pi coding agent with various CI/CD platforms like GitHub, Codeberg, and self-hosted Forgejo. It supports a familiar workflow, minimalistic philosophy, and integrates seamlessly into GitHub issue/PR workflows, providing tools for generating reports, sharing sessions, and automating code reviews.
July 16, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.4.1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code review tool that automates AI-based analysis across various code hosts, providing structured and commentable reviews. It simplifies the setup process by using Code Host Adapters, allowing users to own their review runtime and policy in their repository files.
July 16, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is a lightweight read-only viewer for OpenSpec content that provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It allows developers to navigate through specs, changes, and tasks in a local directory without server deployment or data leaving their machine. The action automates the process of aggregating git worktrees into one view, enabling seamless access to all in-flight changes across multiple branches and worktrees.
July 16, 2026
Graveyard Check
Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check is a tool that scans dependency files to identify abandoned or at-risk packages, providing verified successor recommendations. It supports various ecosystems and provides flags for filtering and output formats. The tool can be used as a CI gate or shell guard on its own by exiting with an error if a package is at-risk or likely abandoned.
July 16, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw action automates the management of Go workspaces by generating and maintaining the go.work file, lints cross-module dependency versions, and runs commands across every module. It solves problems related to managing multi-module Go projects efficiently and ensures consistent dependency versions across all modules. The action supports various commands such as bootstrapping, syncing go.work, linting, running commands in each module, building, testing, vetting, generating code, tidying dependencies, listing modules, adding/removing modules, printing the dependency graph, diffing working tree against a git ref, and performing health checks.
July 16, 2026
Publish updated packages
Version updated for https://github.com/TypeFox/gh-publish-npm to version v0.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing process for npm packages, VS Code extensions, and Open VSX extensions. It ensures that only newer versions are published by comparing them with previously published versions. The action supports token-based authentication for npm and personal access tokens for VS Marketplace and Open VSX. The tool is configured to use OIDC trusted publishing by default unless an explicit npm token is provided for token-based authentication.
July 16, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.88.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
miu-cr is an AI code review tool for CLI, CI, and MCP hosts that automates the process of reviewing staged changes, gate PRs in CI, or drive the engine from any MCP-capable agent. The action provides deterministic engine functionality using LLMs and outputs a stable JSON envelope on stdout, solving problems related to code review automation.
July 16, 2026
Commit via GitHub API
Version updated for https://github.com/vig-os/commit-action to version v0.3.1.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of committing changes to a repository using the GitHub API, enabling the creation of signed commits that bypass branch protection rules. It supports both standalone usage and integration as a module, making it versatile for various use cases in CI/CD pipelines. The action is designed to be type-safe and well-tested, with optimized API usage for handling large files efficiently.
July 16, 2026
Sync Issues and PRs
Version updated for https://github.com/vig-os/sync-issues-action to version v0.3.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sync Issues and PRs Action automates the process of syncing all issues and pull requests from a repository into markdown files, preserving their original content, comments, and metadata. It supports syncing closed items, filtering by issue or pull request numbers, and offers options for customizing output formats and handling attachments. The action can be used with various authentication methods and outputs sync statistics and file paths.
July 16, 2026
PlatformIO Dependency Updater
Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-b1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks for updates to dependencies in a platformio.ini file and creates pull requests when newer versions are available. It supports multiple dependency sources and provides built-in features like automatic versioning and cooldowns. The action is useful for keeping projects up-to-date with the latest library releases and maintaining clean PR histories.
July 16, 2026
void git identity
Version updated for https://github.com/voidmason/git-identity to version v1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action resolves the Git committer identity (name and email) from a token or a PAT, handling various resolution strategies including lookup based on user information. It supports specifying explicit names and emails directly in the action inputs or using default values if no specific pair is found. The resolved pair can be used to configure Git settings or passed to other actions as needed.
July 16, 2026
hreflang-forge
Version updated for https://github.com/wonsukchoi/hreflang-forge to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action, hreflang-forge, generates a sitemap with hreflang alternate links for every page in a Next.js project. It scans the project to identify routes and locales, then creates an XML file detailing each page’s URL structure and hreflang tags. The action is zero-dependency and can be run using Node.js directly or through npm packages.
July 16, 2026
Agent Lint
Version updated for https://github.com/zhupanov/agent-lint to version v2.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a linter for Claude Code, Cursor, and Codex configuration files. It automates the validation of configuration files across multiple categories and provides two lint modes: Basic mode for validating detected configurations and Plugin mode for running the full rule suite when .claude-plugin/ is present. The tool can be integrated into CI workflows using a GitHub Action or used as a pre-commit hook to ensure configuration integrity before committing changes.
July 16, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.494.
This action is used across all versions by 19 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security and quality checks of AI plugin repositories across different platforms (Codex, Claude, Gemini, OpenCode) by generating structured reports, SARIF files, policy results, and submission metadata. It helps identify security vulnerabilities, compliance issues, and trust signals in AI plugins, ensuring they are secure, publishable, and ready for runtime usage.
July 16, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.493.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The summary provides a concise overview of the action’s main purpose, functionality, and problem-solving capabilities.
July 16, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically scans various package managers and ecosystems to detect potential security threats such as malware, code-level vulnerabilities, and supply chain attacks. It generates CycloneDX SBOMs to provide a comprehensive view of dependencies and verifies SLSA provenance, helping organizations identify and remediate risks in their software supply chains.
July 16, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.9.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Boost is a tool designed to help developers and agents manage and save tokens in their output by trimming noise while preserving critical information about task execution. It enhances terminal logs with structured context, reducing verbosity without compromising performance or agent effectiveness.
July 16, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.88.10.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a unified API for accessing 30+ AI providers and models. It allows developers to switch between different providers with a single parameter change and leverages built-in tools and MCP servers. NeuroLink also offers enterprise features like Redis memory and multi-provider failover, and intelligent routing to optimize costs automatically.
July 16, 2026
MathArts Sync Labels
Version updated for https://github.com/matharts/sync-labels-action to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MathArts Sync Labels 是一个 GitHub Actions 动作,用于同步组织内多个仓库的标签。它使用一份标签清单和一份所有权策略,确保只有管理员声明为保留或管理的标签能够被更新、删除或重命名。Action 默认预览变更并只操作策略允许的操作,可以离线校验配置。
What’s Changed 仓库范围与离线校验 新增可选的 repositories.exclude 策略;未配置时保持原有仓库选择行为。 仓库范围按固定顺序应用:全部仓库或 repositories.include,然后是 repositories.exclude,最后是可选的 repository input。 在访问 GitHub 前拒绝重叠、重复、空或无效的仓库选择。 新增 validate_only Action input,无需 GitHub 凭据或网络访问即可校验标签和仓库策略文件。 新增 pnpm validate:config,复用 Action 使用的 GovernanceConfig 规则。 保持 v1.4 inputs、outputs、默认 dry-run 行为、删除安全、重试行为、部分失败计数和 Unicode 处理不变。 明确 changed 在 dry-run 模式报告计划变更,在写入模式报告已完成的变更。 通过全组织排除 dry-run、无凭据离线校验、非法策略一致性及现有 workflow 兼容性验证候选版本。 将稳定错误分类、失败仓库输出、可归档计划文件、并发、缓存和批处理推迟到后续版本。 建议审核发布提交并固定其完整 SHA,而不是可移动版本标签。 验证:pnpm check、Node.js 24 CI、可复现 dist/index.js bundle 比对、Actionlint、CodeQL、全组织排除 dry-run、发布演练、发布后测试及发布后组织预览均通过。
July 16, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.96.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of scanning software assets to identify vulnerabilities, generating a Unified Graph for context and visibility, and serving findings in real-time. It streamlines security operations by providing a unified interface for both internal and external stakeholders to access security information. The action supports various tools and platforms, making it versatile for organizations looking to enhance their cybersecurity posture and streamline incident response processes.
July 16, 2026
AI PR Review (GitHub Models)
Version updated for https://github.com/muhammedshibilm/ai-pr-review-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI PR Review Action is a GitHub Action that uses pre-trained models to review pull requests in your repository. It provides feedback on areas like bugs, security, and readability, with the ability to focus reviews on specific aspects of the code. The action automates the process by running multiple specialized reviews in parallel, allowing for a comprehensive assessment of the PR’s quality.
July 16, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.25.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a Go proxy cache when new module releases are tagged according to semantic versioning conventions (vX.Y.Z and submodule/path/vX.Y.Z). It supports customizing the proxy configuration, import path, and Go version. The action uses actions/setup-go for setting up the Go environment and caches dependencies for faster builds.
July 16, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that automates the consolidation of scattered agent configurations into one canonical AGENTS.md file in a repository, helping to eliminate drift and maintain consistency across different tools. It also provides functionality to apply changes, guard against further drift, and ensure repositories do not rewrite or delete through symlinks. The action can be run with a single command to scan a repository and generate a full checkup report.
July 16, 2026
OSuite Governed Action
Version updated for https://github.com/OndCo/osuite-governed-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the governance of GitHub Actions by creating an OSuite action envelope that includes runtime context and applies policies before the workflow continues. It allows teams to track actions in OSuite, manage approvals, and ensure compliance with governance rules. The action emits outputs for decision, replay link, and proof URL, enhancing transparency and accountability in CI/CD workflows.
July 16, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the evaluation of MCP servers to provide a reproducible grade A-F, ensuring compliance and consistency across different environments. It allows users to quickly check, list, or request grades for servers, verify attestation proofs, and run litmus tests directly from an agent server. The action supports various inputs including npm packages, pypi packages, GitHub repository clones, MCP endpoints, and local entry files, and ensures that the target’s code is executed within Docker sandboxing.
July 16, 2026
MegaLinter Custom Flavor Zensical
Version updated for https://github.com/practicalli-johnny/megalinter-custom-flavor-zensical to version Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-zensical], unable to determine latest release.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action customizes the official MegaLinter Docker image to include only specific linters and optimize it for a smaller size. It solves the problem of having an optimized, lightweight MegaLinter environment by embedding only essential linters like MARKDOWN_MARKDOWN_TABLE_FORMATTER, markdown_rumdl, repository_betterleaks, spell_lychee, and yaml_v8r.
July 16, 2026
RabbitMQ Publish
Version updated for https://github.com/rikkaneko/rabbitmq-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing of UTF-8 payloads to a RabbitMQ or AMQP exchange or queue. It supports various authentication methods, including username/password and mTLS certificate-based authentication, as well as header support for custom routing keys. The action ensures that the connection is validated before publication and provides options for consumer acknowledgment with timeout settings.
July 16, 2026
Droid LLM Hunter
Version updated for https://github.com/roomkangali/droid-llm-hunter to version 1.1.9.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Droid LLM Hunter is an automated security analysis tool designed to detect vulnerabilities in Android applications with high precision. It combines traditional static analysis (SAST) with the contextual understanding of Large Language Models (LLMs) to provide intelligent, risk-filtered findings and active Red Team Assistant capabilities through auto-exploit generation.
July 16, 2026
RW AI Reviewer
Version updated for https://github.com/rw-core/rw-ai-reviewer to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI code review action automates the process of performing AI-based reviews on pull requests by gathering PR context, diff, and customizable instructions. It sends the combined data to a GitHub Models inference API and posts the result as a sticky comment on the PR, along with job summaries and outputs. The action supports extending or replacing built-in review instructions with custom markdown files.
July 16, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.5.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein automates multi-agent deterministic scheduling of CLIs such as Claude Code, Codex, and Gemini CLI in parallel Git worktrees. It uses an HMAC-signed audit chain to track each step of the process and provides signed agent cards for secure delegation. The lineage feature records every adapter file write, ensuring artifact provenance.
July 16, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight read-only viewer that transforms local OpenSpec directories into an interactive, structured interface. It provides features like dashboard overview, spec browsing, change management, Git worktree aggregation, timeline visualization, BDD syntax highlighting, task progress tracking, and full-text search. The tool is available in various forms including web apps, VS Code extensions, and IntelliJ plugins, all designed for read-only access to OpenSpec content without server deployment or authentication.
July 16, 2026
runward gate
Version updated for https://github.com/stranxik/runward to version v0.18.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is a delivery framework designed to structure agentic systems from idea to production. It automates the gating process, ensuring that agents are built and run correctly before deployment, covering six key phases of development: frame, spec kit or open spec, brownfield characterization, floor first (testing), evolution on evidence, governance from day zero, and handover. Runward helps prevent architecture failures by addressing core assumptions of classical distributed engineering and providing a structured approach to the delivery of agentic systems.
July 16, 2026
Pi Review Agent
Version updated for https://github.com/sun-praise/pi-review-agent to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Multi-persona PR review agent using Pi and Litellm AI to automate inline reviews, cache management, and team collaboration on GitHub or Gitea platforms.
What’s Changed Highlights Two-layer verifier suppresses hallucinated findings — rule-based line/file checks plus LLM re-confirmation. Demoted items appear in a collapsible section. Regex grep tool — the walkGrep matcher now accepts regex patterns by default. Cross-model fallback — configure a comma-separated fallback model list (PI_REVIEW_FALLBACK_MODELS) so the agent retries on another model when the primary fails. What’s Changed Added Two-layer verifier to suppress hallucinated findings (#21) Regex support in grep tool Cross-model fallback support (#29) Fixed parseDiffPath handles file paths containing spaces (#25) filterDiff truncates at section boundaries and excludes build artifacts by default (#28) walkGrep glob matching normalizes path separators for Windows compatibility Full Changelog: https://github.com/sun-praise/pi-review-agent/compare/v1.4.0...v1.5.0
July 16, 2026
setup-hcloud
Version updated for https://github.com/vbem/setup-hcloud to version v1.0.6.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Huawei Cloud KooCLI (Huawei CLI) on your runner, supporting Linux, macOS, and Windows. It supports downloading the tool from internal mirrors if needed, and can automatically check its version and accept the privacy statement during installation. The action provides outputs for the download URL, binary path, and version detected after setup.
July 16, 2026
warmup.rocks — CDN Cache Warmer
Version updated for https://github.com/warmup-rocks/warm-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The warmup.rocks CDN Cache Warmer Action automatically triggers a cache warm run on the warmup.rocks service right after a deployment in your GitHub repository. It helps ensure that your CDN cache is hot and ready to serve content to visitors before they arrive, improving performance and user experience. The action uses an encrypted secret for the deploy hook URL and can skip runs if it detects a warm pass in progress or within the cooldown period.
July 16, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cowork-harness, provides a scriptable, CI-friendly test harness to reproduce the observable runtime contract of Claude Cowork. It allows users to test their skills across many scenarios headless and in CI environments without relying on the locked Desktop app. The action supports different fidelity tiers, including replay mode for free demos, linting functionality with Python3, and live testing modes that require a running agent, token, and runtime environment. The summary highlights its main purpose, how it solves the need to test skills in various contexts, and the key capabilities it offers for developers.
July 16, 2026
Kover Report Action
Version updated for https://github.com/yshrsmz/kover-report-action to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support with flexible discovery methods (command-based or glob pattern) and configurable thresholds for different module types and names. The action also provides options to include coverage history and trends in PR comments, making it useful for tracking code coverage improvements over time.
July 16, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action that automates the consolidation of scattered agent configurations into a single canonical file (AGENTS.md) to prevent drift in repository settings such as tools, paths, and package managers. It helps manage agent configurations by providing a full checkup including inventory, conflict evidence, security audit, missing infrastructure gaps, and tech-stack snapshot. The action avoids mutating files or directories that are linked through symlinks.
July 16, 2026
XAI Review
Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.71.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review is a code review tool that leverages AI to automate code reviews, improving efficiency and reducing noise in pull requests. It supports multiple LLM providers, integrates with popular version control systems, allows customizable prompts, and includes agent mode for deeper context exploration. The tool runs automatically within CI/CD pipelines, posting inline comments, summary reviews, and AI-generated replies directly into merge requests.
July 16, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.16.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs Apex unit tests locally using the aer tool, allowing developers to execute and debug Apex code without needing an org. It supports various features like local SObject management, trigger execution, governor limits enforcement, and testing with coverage reports. The action is particularly useful for CI/CD pipelines where developers can quickly validate their code changes before deploying.
July 16, 2026
Initialize GitHub Job
Version updated for https://github.com/PandasWhoCode/initialize-github-job to version v1.3.0.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Initialize GitHub Job composite action automates the setup steps for various programming languages and tools, including security hardening, repository checkout options, multi-language support, build tool setups, and dependency caching. It helps streamline the process of starting a job in GitHub Actions by consolidating common setup tasks. The action supports Node.js, Java, Python, Go, Rust, and Swift, providing flexible configurations for each language and build tool.
July 16, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler automates security and compliance tasks by providing a comprehensive suite of cloud security checks and integrations. It helps organizations identify potential risks, implement automated remediations, and maintain compliance with regulatory standards across various cloud environments.
July 16, 2026
Jira Xport
Version updated for https://github.com/PunteriaCero/Jira-Xport to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Jira-xport GitHub Action exports all tickets from a specified Jira filter to a CSV file. It handles the 3-level hierarchy of Epics → Issues → Sub-tasks and automatically converts time-tracking fields to hours. The tool supports exporting with subtasks and restricting them by labels, and outputs are kept for one day before deletion. Users can run the action through GitHub Actions workflows or locally using Docker.
July 16, 2026
PR Explainer AI
Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Explainer AI is a GitHub Action that automates the process of creating interactive HTML artifacts for pull requests. It turns diffs into clear learning experiences by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes. The action helps teams align on changes and provides durable, visual understanding that can be revisited later.
July 16, 2026
raviqqe/muffy
Version updated for https://github.com/raviqqe/muffy to version v0.3.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of static websites using Muffet, a tool for checking website content for issues like broken links and accessibility problems. It provides a straightforward way to ensure that a website is functional and accessible before deployment.
July 16, 2026
setup-tq
Version updated for https://github.com/remarkablemark/setup-tq to version v1.0.13.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the tq tool, a TOML query language interpreter, in your GitHub Actions workflow. It allows you to automate tasks such as extracting specific information from TOML files, making it useful for projects that use TOML configuration files.
July 16, 2026
SBOMForge
Version updated for https://github.com/Richonn/SBOMForge to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SBOMForge is a GitHub Action that automates the creation, signing, and attaching of Software Bill of Materials (SBOM) for projects using Syft and Cosign. It helps ensure compliance with security requirements like SLSA by providing a zero-config solution to generate and attach SBOMs to GitHub releases.
July 16, 2026
Flint AI Inventory Scan
Version updated for https://github.com/sandbox-quantum/flintai-codescan-action to version v5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static analysis of code for detecting AI assets using Flint AI. It provides an inventory of AI assets found in your repository, enriches it with additional information, and sends the results to your Flint AI instance. The action supports various LLM models and requires API keys for authentication.
July 16, 2026
memi design CI
Version updated for https://github.com/sarveshsea/memi to version v2.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
memi is an AI-driven design quality assurance tool that automates the auditing of real product interfaces, remembers design systems, and prevents UI regressions before merge. It works with Grok Build, Codex, Claude Code, Cursor, Hermes, OpenCode, OpenClaw, and other MCP clients. The tool provides skills for audit, remember design system context, enforce design CI gates, and more, making it a valuable tool for developers to ensure code quality and prevent regressions in UI development.
July 16, 2026
SEO.ai trigger pusher event
Version updated for https://github.com/seo-ai/pusher-trigger to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action triggers an event on a Pusher channel, providing a simple and reusable way to send custom events with JSON payloads. It automates the process of integrating Pusher notifications into CI/CD pipelines or other automation workflows without requiring manual setup or configuration.
July 16, 2026
The Slack GitHub Action
Version updated for https://github.com/slackapi/slack-github-action to version v4.0.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,858 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Slack GitHub Action automates sending data to Slack and running commands, providing features for using webhooks, API methods, incoming webhooks, and Slack CLI commands with service tokens. It simplifies integration between GitHub workflows and Slack, enabling seamless communication and automation.
July 16, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.51.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Console CensorChecker, is a PowerShell script that uses Tcping to perform batch pinging and checks the availability of monitoring services. It helps identify if there are network censorship issues by measuring ping latency to specified targets. The action supports various installation methods through PowerShell modules or GitHub Actions integration, making it useful for developers and network administrators who need to check service connectivity without bypassing review devices.
July 16, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static site generator written in Go. It converts Markdown files with YAML frontmatter into a complete website, including features like sitemap, search index, and responsive images. It supports various deployment options such as Cloudflare Pages, GitHub Pages, and Netlify. The action automates the process of building websites from markdown content efficiently.
July 16, 2026
aidemo Demo Video
Version updated for https://github.com/tandryukha/aidemo to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to generate polished demo videos from code interactions using an AI coding agent. It automatically renders deterministically and updates with each change in the product, eliminating the need for re-recording and API keys. The action automates tasks such as recording a 45-second demo of a checkout flow and generating MP4s with voiceover, captions, and auto-zoom features.
July 16, 2026
Bumpkin Release Planner
Version updated for https://github.com/trybumpkin/bumpkin to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bumpkin automates the creation of reviewed release candidates by analyzing merged pull requests, proposing version bumps and generating public changelogs. It helps teams with inconsistent commit conventions manage releases efficiently and ensures that releases are thoroughly reviewed before publication. The action is suitable for teams publishing GitHub Releases from merged PRs, especially those dealing with mixed-merge workflows or repositories with varying commit discipline.
July 16, 2026
SR - Semantic Release
Version updated for https://github.com/urmzd/sr to version v8.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sr automates the release engineering process using semantic versioning from conventional commits. It helps users manage releases by providing a CLI tool that can plan, prepare, and release projects efficiently. Key capabilities include:
July 16, 2026
Setup Vamposer
Version updated for https://github.com/ValaFoundation/vamposer to version v0.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vamposer is a tool that automates the dependency management of Vala projects using Meson. It resolves package dependencies, installs system dependencies where possible, and generates necessary files to integrate with Meson subprojects. The action is designed to streamline the development process by handling dependency resolution and integration tasks automatically.
July 16, 2026
Commit via GitHub API
Version updated for https://github.com/vig-os/commit-action to version v0.3.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of committing changes to a repository using the GitHub API, creating signed commits that bypass branch protection rules. It supports modular design and provides type safety with TypeScript. The action can be used as a standalone GitHub Action or imported as a module for integration into larger workflows.
July 16, 2026
UCP Conformance (spck)
Version updated for https://github.com/vishkaty/spck-conformance-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action adds a behavioral UCP conformance gate to your CI pipeline. It runs the spck-conformance suite against your UCP merchant server, checking for MUST deviations and ensuring compliance. The action supports both server and agent-side modes, allowing you to verify shopping agent functionality. It outputs JUnit reports with spec citations for any deviations found during testing.
July 16, 2026
Prune Old GitHub Actions Runs
Version updated for https://github.com/yanovian/delete-old-actions to version v1.0.12.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action delete-old-actions is designed to remove old GitHub Actions runs from repositories. It solves the problem of keeping repository clean by automatically deleting runs that are older than a specified number of days or keeping a certain number of the most recent runs. The action can be configured to run as part of a schedule and supports dry-run mode for testing purposes.
July 16, 2026
Open License Auditor
Version updated for https://github.com/yanovian/open-license-auditor to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Open License Auditor GitHub Action scans all dependencies in a repository to identify risky open source licenses and posts comments on pull requests. It supports various package managers including npm, Yarn, pnpm, pip, Poetry, and more, and flags problematic licenses as critical or warning. The action automatically detects licenses and provides detailed information about each dependency, helping teams manage their software dependencies effectively.
July 16, 2026
judgegate
Version updated for https://github.com/yashchimata/judgegate to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary judgegate is a CI trust gate for LLM judges that measures their reliability against human labels using Cohen’s kappa and bootstrap confidence intervals. It helps teams avoid relying solely on AI judgments by verifying their accuracy and identifying noisy or unreliable judges. The action verifies a judge, asks the label budget question, stops labeling early, and validates any labels file before running.
July 16, 2026
zizmor-action
Version updated for https://github.com/zizmorcore/zizmor-action to version v0.6.0.
This action is used across all versions by 6,734 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of zizmor, a security analysis tool, within GitHub Actions workflows. It helps organizations integrate comprehensive security assessments into their CI/CD pipelines to identify and remediate vulnerabilities quickly. The action supports both public and private repositories and provides options for advanced security features, such as collecting and reporting findings via GitHub’s Advanced Security integration.
July 15, 2026
Magento 2 build deploy v.05
Version updated for https://github.com/brohon/magento-actions to version v.58.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates various tasks for Magento and PWA-Studio CI/CD, including unit tests, static code analysis, build processes, and zero-downtime deployments. It supports different versions of Magento and uses Docker containers to manage services like MySQL and Elasticsearch. The action is designed to be integrated into a repository’s workflows, allowing users to easily set up and run automated builds and checks on their Magento projects.
July 15, 2026
AI Diff Reviewer
Version updated for https://github.com/DailybotHQ/ai-diff-reviewer to version v1.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the AI-driven code review process for your Git diffs, providing inline comments and severity-based merge gating. It runs on every pull request and supports both CI and local coding-agent skills with shared configuration files for seamless integration.
July 15, 2026
MUADDIB Scanner
Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.170.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MUAD’DIB is a free supply-chain scanner for npm and PyPI that detects known malicious packages, install-time RCE, credential-then-exfiltration flows, obfuscated payloads, binary droppers, and other suspicious behavioral patterns. It combines parallel scanning, deobfuscation, inter-module analysis, compound scoring, and a sandbox environment to provide comprehensive detection capabilities without telemetry.
July 15, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.39.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action triggers a test run in DoesQA and waits for it to complete. It automates CI/CD testing by providing input parameters for key data such as API keys, account IDs, and tags, and outputs the final status and report URL of the test run. The action also supports creating Check Runs with automatic or custom labels for better integration with GitHub’s workflow system.
July 15, 2026
npm-pkg-lint
Version updated for https://github.com/ext/npm-pkg-lint to version v5.1.12.
This action is used across all versions by 37 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, npm-pkg-lint, is an opinionated linter designed to validate NPM packages. It checks for syntactic correctness and adheres to strict guidelines, ensuring that the tarball and package.json metadata are technically valid according to specification. The action helps ensure that package metadata is clear, concise, and accurate, which is crucial for maintaining the integrity of NPM packages.
July 15, 2026
Github Action Podcast Generator workflow-1
Version updated for https://github.com/hackerone07-cmd/podcast-generater-github-actions to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates podcasts by converting YouTube videos into MP3 files using FFmpeg. It automates the process of downloading audio from YouTube, converting it to MP3 format, and storing the result in a specified directory. This action helps streamline content creation for podcast producers by eliminating manual steps and saving time.
July 15, 2026
GitHub Wiki Organiser
Version updated for https://github.com/hayat01sh1da/github-wiki-organiser-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action organises a GitHub wiki by regenerating the Home.md and _Sidebar.md files based on the Owner/Category declared at the beginning of each page, grouping them accordingly (English and Japanese labels built in). It also allows exporting reports or generating LLM exports of pages with unknown owner or category. The action is powered by the spreen-wiki PyPI package and requires a token to check out and push changes to the wiki repository.
July 15, 2026
jk-neospec
Version updated for https://github.com/jedi-knights/neospec to version v0.2.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, isolates tests in a clean environment, instruments Lua coverage using debug.sethook, and generates reports in various formats that are compatible with CI pipelines. This allows developers to test their plugins effectively without requiring system installations or complex shell scripts.
July 15, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.87.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 24+ AI providers and 100+ models under one consistent API. It provides production-ready solutions for integrating AI into any application, with features such as switchable providers, built-in tools, enterprise-grade features like Redis memory and multi-provider failover, and intelligent routing optimizations.
July 15, 2026
jira-cve-action
Version updated for https://github.com/levigo/jira-cve-action to version v1.23.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Jira-CVE-Action is an action that takes a JSON output from the Trivy Action and creates Jira issues for all identified CVEs under a predefined parent issue. If the parent issue is on a sprint board, it automates adding sub-tickets to the sprint. The action also allows sharing issues across multiple GitHub projects within the same Jira project by tagging them with specific project versions. It automatically moves issues between states (waiting or ready) based on whether a fix version is included in the scan results.
July 15, 2026
Repository Languages and CodeQL Support Map
Version updated for https://github.com/lfventura/list-repository-languages to version v4.0.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, list-repository-languages, automates the detection of repository languages and maps them to the CodeQL matrix. It supports two detection methods: linguist-js (default) and using the GitHub API. The action helps in accurately identifying the programming languages in a repository by either analyzing the local checkout or querying GitHub’s API, depending on user preference. This is particularly useful for integrating language-based analysis into CI/CD pipelines with CodeQL.
July 15, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.5.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, crab’d, is a versatile coding assistant that automates the implementation of whole issues and reviews pull requests using various AI models (Anthropic, OpenAI, OpenRouter, or local Ollama). It supports any model on both GitHub and Forgejo platforms, offering a customizable workflow for developers.
July 15, 2026
JulesOps
Version updated for https://github.com/mkshp-dev/julesops to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary JulesOps is a GitHub Action that automates the process of running Google Jules tasks using pull requests, comments, and labels. It helps prevent duplicate runs, retries failed operations, synchronizes PR states, recovers from failures, and works with any repository. The action uses GitHub Actions for local workflow management and a state machine driven by GitHub labels to handle task execution and status updates.
July 15, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.97.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based tool designed to enhance collaboration in AI-driven development. It uses plain markdown lessons stored in the repository, which are compiled into lint rules that enforce project rules and context. This approach avoids architectural mistakes by keeping documentation and lessons alongside the code, ensuring consistency across sessions. Totem provides a deterministic zero-LLM linter for linting and an offline queryable knowledge index derived from these lessons, enhancing both the efficiency of development cycles and the integrity of architectural decisions.
July 15, 2026
Review Buddy AI
Version updated for https://github.com/nexoral/ReviewBuddy to version v6.28.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Review Buddy is an AI-powered GitHub Action that automates code reviews, focusing on quality, metadata updates, best practices suggestions, and interactive feedback. It helps improve the efficiency of code reviews by providing intelligent comments, recommendations, and summaries.
July 15, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool designed to help manage agent configurations across different repositories. It consolidates scattered agent config files into one canonical AGENTS.md, providing visibility into drift, conflict evidence, security audits, missing infrastructure gaps, and tech-stack snapshots. The action ensures that the repo does not forget about stale instructions by using write-capable stubs, drift-fixing commands, and guards.
July 15, 2026
Turbo Repo Sync
Version updated for https://github.com/nullptr-t-oss/turbo-repo-sync to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Turbo Repo Sync is a GitHub Action that optimizes Android-style manifest-based project synchronization by using concurrent downloads with aria2c. It provides flexibility in specifying local or remote manifest.xml locations, supports project overrides, handles Git LFS, and works with multiple forge types. The action can be integrated into workflows to quickly set up source trees for building or testing purposes.
July 15, 2026
Obviously Concept Scanner
Version updated for https://github.com/Obviously-Not/concept-scanner to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Concept Scanner is an open-source tool that automates the process of identifying and analyzing technical concepts in codebases using local or remote language models. It helps identify distinctive engineering mechanisms, scores them on various quality axes, and saves the results locally. The action supports both Ollama and OpenAI-compatible providers for running the analysis.
July 15, 2026
Runtime Contract Check
Version updated for https://github.com/piotr-adamski/runtime-contract to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action for runtime-contract checks whether environment variables used by a specific application component are actually supplied to that component in the correct build or runtime phase. It automates the process of static analysis and ensures that configuration contracts are adhered to, without executing code or accessing secret values. The action provides outputs for exit codes, result files, and CLI version verification.
July 15, 2026
Star History CI
Version updated for https://github.com/ranxi2001/star-history-ci to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Star History CI GitHub Action automates the process of keeping star history charts alive in READMEs by rendering, renaming, and publishing SVG files to a stable output branch. It solves the problem of maintaining up-to-date star chart visualizations without manually updating images in the default repository branch. The action runs from source within the repository and does not rely on third-party services for rendering or publishing, ensuring security and control over the data.
July 15, 2026
SFDT for Salesforce
Version updated for https://github.com/scoobydrew83/sfdt to version v0.18.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment, testing, and release management of Salesforce changes using the @sfdt/cli tool from the SFDT suite. It provides interactive workflows with preflight validation and tagging, automated release manifest generation, parallel Apex test execution, code and test quality analysis, a pre-release checklist, rollback support, smoke tests, org metadata drift detection, multi-package project support, smart package.xml generation, AI deployment error log interpretation, AI-generated PR descriptions, AI-powered code review, and more. The action supports CI/CD pipelines for GitHub, GitLab, Azure, and Bitbucket and can be integrated with other tools like Slack, MS Teams, Google Chat, email, webhook, and Grafana Loki.
July 15, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Console-CensorChecker, is a PowerShell-based Tcping batch probe and review detection script designed to check the availability of monitoring services and detect network censorship. It supports multiple platforms and can be installed via PowerShell Module or invoked as a command in PowerShell scripts or within a workflow using GitHub Actions.
July 15, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw action automates the management of Go workspaces, including generating and maintaining go.work, linting cross-module dependencies, running commands across modules, and checking the release contract. It helps in managing multi-module projects efficiently by handling module discovery, version consistency, dependency alignment, and CI readiness.
July 15, 2026
Feishu Notification
Version updated for https://github.com/Waybox-AI/feishu-notification to version v1.0.20.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Feishu Notification is a GitHub Action that sends interactive card notifications to [Feishu (Lark)] channels when pull request events occur. It automates the process of notifying team members about new issues, merge requests, and commits. The action supports different colors for different types of events and handles PRs merged into main, with others being skipped silently.
July 15, 2026
wcagc accessibility check
Version updated for https://github.com/WCAG-Compliance/wcagc-ci to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses the wcagc service to automate accessibility checks on URLs, comparing them with a saved baseline and reporting findings for integration into the review workflow. It covers part of WCAG and EN 301 549, but does not modify a site. The action emits URL-level workflow annotations and provides a summary of coverage limitations and results.
July 15, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a technical tool designed to test Claude Cowork skills through scripting and CI pipelines. It reproduces the observable runtime contract closely enough to allow testing skills across various scenarios without using the locked Desktop application, thereby simulating sealed filesystems, default-deny egress, and MCP-only cross-boundary limitations. This helps in identifying issues related to behavior and restrictions before deploying a skill in production environments.
July 15, 2026
tofu-garnish
Version updated for https://github.com/lowlydba/tofu-garnish to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The tofu-garnish GitHub Action automates the process of publishing OpenTofu/Terraform outputs into a simple, readable static page on a repository’s GitHub Pages, enhancing visibility and accessibility for engineers in finding resource ARNs without running tofu output or manually navigating through state. It supports structure-aware HTML rendering, discrete multi-workspace publishing, sensitive outputs masking, and plug-and-play integration with dflook/terraform-github-actions.
July 15, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.4.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede is an open-source static application security testing (SAST) tool that focuses on detecting authorization flaws, including the CWE-639 IDOR vulnerability. It provides 100% recall of known CVEs and a low level of noise in production code compared to existing tools like Semgrep, CodeQL, and Bandit. Ansede offers full offline functionality and supports multiple programming languages.
July 15, 2026
TestivAI Visual Report
Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness-webdriverio@0.2.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action enables local-first visual regression testing for modern web applications using TestivAI SDKs. It provides a fully self-contained solution with no account or API key, using Playwright and WebdriverIO adapters to capture, diff, and report changes in UI elements without network interaction. Users can approve baselines directly from PR comments via the /testivai approve command.
July 15, 2026
Mozilla SOPS Installer
Version updated for https://github.com/mdgreenwald/mozilla-sops-action to version v2.1.1.
This action is used across all versions by 241 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a specific version of the SOPS binary on the runner, automating tasks such as securing sensitive information in configuration files. It provides a caching mechanism to speed up future runs and supports various platforms through native binaries. The action also includes features like handling latest versions and pinning for security.
July 15, 2026
invAIriant audit gate
Version updated for https://github.com/mindicator/invAIriant to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: invAIriant is a CI/CD tool designed to audit codebases for architectural invariants, providing evidence-based architecture audits. It helps gate merges based on real findings and prevents architectural drift by ensuring every candidate survives adversarial evidence checks before becoming a finding. The tool supports a set of review lenses that discover and verify issues before severity gates, making it useful for maintaining robust architectures during AI-assisted development.
July 15, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.96.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Totem GitHub Action automates linting, helping developers enforce architectural guidelines and maintain code quality by reading and writing to a file-based substrate of plain markdown lessons. It provides a deterministic, offline lint engine that runs in under 2 seconds, reducing friction and improving collaboration among AI coding agents.
July 15, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that helps automate the process of consolidating scattered agent configurations into one canonical file (AGENTS.md). It ensures that all references to old or outdated tools are replaced with pointers to existing files, preventing future drift and confusion. The action also provides safeguards to prevent accidental modifications or deletions through symbolic links.
July 15, 2026
XAI Review
Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.70.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review is an AI-powered code review tool that automates the review process, using LLMs to identify potential improvements in code quality and consistency. It integrates seamlessly with popular version control systems like GitLab, GitHub, and Bitbucket, allowing teams to focus on code development rather than managing reviews manually. With customizable prompts and agent mode, it can explore the repository for deeper insights before generating detailed reviews, making the process faster and more efficient.
July 15, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.15.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Apex unit tests locally, providing developers with a way to run and debug their Apex code without needing an org. It supports various Salesforce functionalities such as SObjects, database operations, triggers, validation rules, flows, and testing framework features like @IsTest.
July 15, 2026
PatchRail CI Triage
Version updated for https://github.com/patchrail/ci-triage-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PatchRail CI Triage Action classifies a failed CI log locally using the patchrail CLI, providing a remediation guide as a job annotation and step summary. It handles logs correctly by redirecting stderr to the output file and supports both local files and raw log text inputs, while also allowing for redaction of sensitive information. The action is designed to be read-only and does not interact with external services or open pull requests.
July 15, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and onboarding process of a new API repository by leveraging Postman’s suite to bootstrap a workspace, upload an OpenAPI specification, generate collections for smoke testing and contract enforcement, and integrate with CI/CD workflows. The action handles environment creation, mock server configuration, and runs automated tests using JUnit output, ensuring that the repository is fully equipped with standards-grounded testing mechanisms.
July 15, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable contract tests. This action helps developers automate the setup process for testing APIs in their projects by providing comprehensive test coverage and enforcing standards through various protocols.
July 15, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action exports Postman collections and environments into a repository and automates CI, mock servers, and monitors around them. It solves the problem of managing API testing tools in repositories by providing seamless integration with Postman’s API and GitHub Actions workflow files. The action also supports generating CI workflows for easy deployment and monitoring setup.
July 15, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Postman Onboarding: Smoke Flow, reshapes a generated Postman Smoke collection to match a curated flow.yaml and optionally injects runtime auth for OAuth2 and API keys. It is part of the Postman API Onboarding suite and requires credentials such as postman-access-token, which is minted by postman-resolve-service-token-action. The action runs entirely through the Postman gateway under the token and can handle both US and EU data residency settings for consistent region calls.
July 15, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.28.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider is a GitHub Action that automates the validation and comparison of new methods against an organization’s codebase. It provides draft PRs with a self-review, handles preflight checks and issues, supports branch-only mode for exploring multiple candidates without committing to any one, and allows quickstart installation via CLI tools. The action uses Anthropic Opus or z.ai GLM-5.2 as model backends, with configurable costs based on the backend used.
July 15, 2026
Foreman Agent Review Gate
Version updated for https://github.com/rohitkumarmanne-442/Foreman to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Foreman is a local code review tool that helps ensure AI-generated changes are verified. It automatically checks each claim made by AI agents against the actual code they produced, ensuring that claims are supported with verification commands.
July 15, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.34.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: rumdl is a high-performance, Rust-based Markdown linter and formatter that offers speed, extensive lint rules, automatic formatting with --fix, zero dependencies, and multiple installation options. It supports various Markdown flavors and provides detailed error reporting, making it suitable for projects requiring consistent and best-practice markdown files.
July 15, 2026
SFDT for Salesforce
Version updated for https://github.com/scoobydrew83/sfdt to version vscode-v0.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates various aspects of Salesforce development, including deploying changes, testing, and monitoring. It supports multi-package projects and provides AI-driven features for error interpretation, PR descriptions, and more. The action simplifies CI/CD processes by offering pre-built templates for common platforms and integrates with multiple notification channels.
July 15, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It solves the problem of automating the process of generating static websites from content written in Markdown and YAML. The key capabilities include Markdown-to-HTML conversion, built-in themes, template engines (such as Pongo2, Mustache, and Handlebars), and support for deployment to various platforms like GitHub Pages, Netlify, Vercel, and FTP/SFTP.
July 15, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.58.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the initialization of Nix-based repositories by performing several key tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting Nix configuration from a flake. It also supports caching with Niks3 and loading development shell environments via nicknovitski/nix-develop. The action is designed to run efficiently and works across various runners including self-hosted, Gitea, and Forgejo.
July 15, 2026
gw - Go workspaces
Version updated for https://github.com/Toyz/gw to version v0.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw automates the management of Go workspaces by generating and maintaining go.work, lints cross-module dependency versions, and runs commands across every module. It solves the problem of managing multiple Go modules in a workspace, providing tools like init, sync, and lint to bootstrap, update, and validate the workspace configuration.
July 15, 2026
New Behavioral Health Practices Weekly
Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads the latest Behavioral Health NPI leads from the CMS weekly file. It provides a free preview of 15 current records as clean JSON and can run a full edition in the buyer’s Apify account, charging $9 plus platform usage or refusing to run without both a token and an explicit total-charge cap.
July 15, 2026
PlatformIO Dependency Updater
Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-a2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks for dependency updates in a project’s platformio.ini, identifies newer versions, and creates pull requests if available. It supports various dependency sources and provides features like pre-release versions and label application. However, it requires dependencies to be pinned to specific versions and does not support version ranges. The action is designed to manage multiple dependency PRs and handle inactive repositories.
July 15, 2026
Zephyr Preview Environments
Version updated for https://github.com/ZephyrCloudIO/zephyr-preview-environment-action to version v0.2.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the creation, update, and cleanup of Zephyr preview environments for pull requests in a GitHub repository. It ensures that every PR gets a live preview deployment with a URL posted as a comment, aiding in code review processes by providing real-time feedback on changes. The action supports both personal and server tokens for authentication, allowing users to choose the most suitable method based on their project’s security requirements.
July 14, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.33.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler is an open-source tool designed to automate security and compliance checks in any cloud environment. It offers a wide range of security checks, remediation guidance, and compliance frameworks to help organizations stay secure and compliant with various regulations and standards.
July 14, 2026
esc-action
Version updated for https://github.com/pulumi/esc-action to version v3.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 199 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Pulumi ESC action automates the process of securely managing and injecting secrets into GitHub Actions workflows using Pulumi’s Environment, Secrets, and Configuration service. It simplifies the management of sensitive information by providing a seamless integration with popular secret stores and CI/CD platforms, ensuring that secrets are only accessible to the necessary actions.
July 14, 2026
action-semver
Version updated for https://github.com/quike/action-semantic-release to version v3.15.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action-semantic-release GitHub action automates the process of releasing projects using semantic versioning with semantic-release. It simplifies the release workflow by handling versioning, generating changelogs, and publishing releases to various platforms. This action is particularly useful for open-source projects where continuous integration (CI) and deployment (CD) are automated, ensuring that all team members follow semantic versioning practices.
July 14, 2026
ZeroPatch CI
Version updated for https://github.com/rdx644/ZeroPatch-CI to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates evidence-first security assessments for GitHub Actions workflows by analyzing five high-confidence controls, identifying potential vulnerabilities, and generating a draft remediation artifact. It restricts transformations to approved SHA pins and least-privilege permissions, ensuring secure workflow execution. The action also provides an API that rejects unsupported or ambiguous findings, requiring manual review. The tool runs as a standalone application or Docker container, with options for running locally or in a production environment.
July 14, 2026
Claude BugBot
Version updated for https://github.com/rekpero/claude-bugbot-github-action to version v1.0.12.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates automated PR bug analysis using Claude Code CLI, providing inline review comments on exact lines where issues are detected. It runs directly on top of Claude Code and is free to use with any Claude Pro or Max subscription without paying for a Cursor subscription. The action focuses only on real bugs and handles large diffs gracefully by truncating at 200KB.
July 14, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.24.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and comparison of new methods against an organization’s codebase by integrating them into real call sites, providing a self-review process and handling issues when preflight, validators, or self-review routes the paper to discussion. It supports various model backends like Anthropic Opus and z.ai GLM-5.2 for different scenarios, including exploration and branch-mode exploration. The action is designed to streamline the workflow by running coding agents in ephemeral runners and handling multiple candidates per week efficiently.
July 14, 2026
codemetrics complexity gate
Version updated for https://github.com/richardwooding/codemetrics to version v0.12.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action checks pull requests to ensure they do not introduce functions with high cyclomatic or cognitive complexity, using code metrics for multiple programming languages. It automates the computation of these metrics and integrates into GitHub workflows to gate out complex changes.
July 14, 2026
file-search-on review gate
Version updated for https://github.com/richardwooding/file-search-on to version v0.119.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The file-search-on action automates file searches based on metadata and content types using CEL expressions. It helps find files that match specific criteria, such as PDFs with more than 10 pages or images taken in a certain area. The tool supports 74 formats across 13 content type families and is designed to be used in both Claude Code and the command line.
July 14, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.33.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
rumdl is a high-performance Markdown linter and formatter written in Rust, designed to speed up linting tasks with its Rust-based implementation. It includes 76 lint rules covering common Markdown issues and offers automatic formatting with the --fix flag for files and stdin/stdout. The tool supports multiple Markdown flavors, is zero-dependency, highly configurable, and has a modern CLI interface with detailed error reporting.
July 14, 2026
SchemaCrawler (Local) Action for GitHub Actions
Version updated for https://github.com/schemacrawler/SchemaCrawler-Local-Action to version v17.12.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of a database schema report using SchemaCrawler, a tool for discovering and documenting databases. It installs SchemaCrawler locally on the runner and allows users to specify database connection details such as URL, user, password, and driver class. The report can be generated as a CSV file or in XML format, providing insights into the database structure.
July 14, 2026
SFDT for Salesforce
Version updated for https://github.com/scoobydrew83/sfdt to version v0.18.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SFDT GitHub Action automates Salesforce deployment and testing processes, including interactive workflows, automated release manifest generation, parallel Apex test execution, code and test quality analysis, pre-release validation checklist, deployment rollback, post-deploy smoke testing, org metadata drift detection, multi-package project support, smart package.xml generator, AI deployment error log interpreter, AI-generated PR descriptions and Slack messages, AI-powered code review, test failure analysis, changelog generation, release notes, org metadata comparison, local web dashboard, smart delta deployments, native org health & operations suite, CI/CD pipeline templates, multi-channel notifications, plugin architecture, and compatibility with any Salesforce DX project.
July 14, 2026
Shieldly — AI-Powered Security Analysis
Version updated for https://github.com/shieldly-io/action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses AI-powered security analysis to identify and report potential security vulnerabilities in AWS infrastructure defined by CloudFormation templates or CDK stacks. It checks IAM policies, posts findings as a PR comment, and fails the build if issues meet a severity threshold set by the user. The action requires an API key for authentication and is suitable for use in CI environments to ensure secure deployment practices.
July 14, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Console-CensorChecker GitHub Action automates the process of checking for network censorship by performing TCP ping tests on specified domains or IP addresses and provides a simple interface for developers to integrate this functionality into their workflows. It helps identify if a domain or service is blocked by content filters or other security measures, ensuring that applications can operate smoothly in environments with restricted access.
July 14, 2026
Graveyard Check
Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check automates the discovery and recommendation of maintainers for abandoned dependencies, helping users identify packages that are effectively dead. It provides a comprehensive scan of project dependencies across various ecosystems (npm, PyPI) to determine which ones may require migration, offering verified community successors as recommendations.
July 14, 2026
Set up Rocq
Version updated for https://github.com/tchajed/setup-rocq to version v1.8.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Rocq using OPAM with caching capabilities to speed up future installations, especially for developers who frequently work on projects that depend on Rocq. It supports specifying a specific version or the latest stable release of Rocq, as well as additional OPAM repositories and customizing which OPAM files are used to generate a cache key.
July 14, 2026
cargo-oxidate
Version updated for https://github.com/timweri/cargo-oxidate to version v0.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cargo.lock for packages that are either too new (potentially introducing vulnerabilities) or too old (stale). It automates the process of identifying and flagging these packages based on specified age thresholds. The action also provides options to exempt certain packages, handle missing publish dates, and include caching features for improved performance.
July 14, 2026
Build Beet project
Version updated for https://github.com/Trioplane/action-build-beet-project to version v5-beta3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for a Beet project, generating data packs, resource packs, and unknown files. It outputs these as JSON arrays and the built directory. The action can be used to streamline the release of Beetle projects by creating ZIP archives of the generated content and uploading them to GitHub releases.
July 14, 2026
Symfony Security Auditor
Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.15.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Symfony Security Auditor is an AI-powered multi-agent security auditor for Symfony applications that targets application-level logic flaws missed by traditional SAST tools. It uses an adversarial Attacker agent to find vulnerabilities and a skeptical Reviewer agent to cull false positives, emitting validated reports in various formats. The standalone CLI or Symfony bundle can be used to audit projects with minimal footprint.
July 14, 2026
PlatformIO Dependency Updater
Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-a1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PlatformIO Dependency Updater is a GitHub Action that checks for updates to dependencies listed in the platformio.ini file of a project. It automates the process of creating pull requests when newer versions are available, resolving issues such as unresolved dependencies and providing links to release notes and changelogs. The action supports multiple dependency sources and keeps track of open dependency pull requests to avoid duplicates and ensure updates remain current.
July 14, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.19.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Spaces, a cloud-based platform for developers. It simplifies the setup process by handling dependencies and configurations automatically, ensuring that new environments or projects are ready for development with minimal manual intervention.
July 14, 2026
spaces checkout run
Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action for executing a spaces checkout/spaces run sequence using the spaces CLI automates the process of checking out and running a workspace on GitHub Actions. It solves the problem of integrating workspace deployment into CI/CD pipelines, providing users with a simple way to automate the setup and execution of workspaces using the spaces CLI. The action is particularly useful for developers who need to build, test, or deploy workspaces in their CI/CD processes.
July 14, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates a headless test harness for Claude Cowork skills. It allows developers to reproduce the observable runtime contract of the platform closely enough for automated testing across various scenarios and CI jobs without needing a locked Desktop app. The action supports different fidelity tiers, including a free demo (replay), linting with python3, live tiers requiring Claude Desktop, token, Docker, or Lima, and provides debugging tools to understand session outputs.
July 14, 2026
Delete Old GitHub Actions Runs
Version updated for https://github.com/yanovation/delete-old-actions to version v1.0.7.
This action is used across all versions by 39 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action deletes old GitHub Actions runs to keep repositories clean. It automates the process of removing unnecessary runs, helping maintain a tidy repository history. Users can set parameters like the number of days ago and how many latest runs should be kept. The action also provides a dry-run option to preview what will be deleted before executing the deletion.
July 14, 2026
Prune Old GitHub Actions Runs
Version updated for https://github.com/yanovian/delete-old-actions to version v1.0.11.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action deletes old GitHub Actions runs in your repository to keep it clean. It helps automate tasks like managing large run logs and reducing costs associated with long-running actions. The action can be configured to delete runs based on age or retain a certain number of the most recent runs, making it useful for maintaining a clean and efficient workflow.
July 14, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.468.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action scans AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to evaluate security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF, policy results, and submission metadata while aligning with the main scanner release train. The action is available as a Marketplace-ready GitHub Action for Hashgraph Online’s AI plugin scanning capabilities.
July 14, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.468.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The HOL AI Plugin Scanner GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It aims to ensure security, publishability, runtime readiness, and trust signals by emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with existing workflows and provides advanced distribution paths for enterprise runners.
July 14, 2026
Holon Solve
Version updated for https://github.com/holon-run/holon to version v0.29.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Holon is a local workbench that provides agents with a continuous working context, organizing tasks and waits explicitly as “Work,” preserving state and context. It supports event-driven wait and wake mechanisms and allows clear separation of operator input, external events, tool results, and execution traces. Holon runs in the real working environment for local repositories, shell, worktrees, and development toolchains.
July 14, 2026
Self Merge Sentinel
Version updated for https://github.com/inakam/claude-code-actions-self-merge-sentinel to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically determines whether to approve or require human review for PRs based on a set of rules defined in a YAML file. It uses Claude AI to analyze the changes and make decisions, updating PR comments and labels accordingly. The action supports bot actors and integrates with Anthropic and Cloud provider credentials, allowing for customizable settings like model configurations and API URLs.
July 14, 2026
jk-publish-test-results
Version updated for https://github.com/jedi-knights/publish-test-results to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, publish-test-results, automates the process of publishing multi-format test results as a drilldownable per-test check-run in GitHub. It supports ten different input dialects and provides clickable annotations on the diff for every test, making it easier to trace failures directly to source lines. The action is designed for Go, Python, and other languages, and it leverages Go’s fast start time for efficient execution.
July 14, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.9.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Boost is a smart token savings tool that reduces the noise in agent output by trimming what’s safe to drop while preserving essential context. It trims only non-sensitive information from noisy logs, allowing agents to focus on important details like errors, timings, and cache hits.
July 14, 2026
Pipelock Agent Security Scan
Version updated for https://github.com/luckyPipewrench/pipelock to version v3.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipelock is an AI-powered firewall designed to monitor and control secret exfiltration, prompt injection, and SSRF within mediated networks. It inspects content using various protocols (HTTP, WebSocket, CONNECT, MCP, A2A) and generates mediator-signed action receipts that can be verified outside the agent runtime. This ensures a content-aware decision is made without relying on blind trust in agent behavior.
July 14, 2026
TestivAI Visual Report
Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness@1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates local-first visual regression testing for web applications using TestivAI SDKs. It provides a self-contained HTML report with DOM-aware noise hints to identify real changes and render noise, allowing developers to focus on meaningful UI improvements without false positives. The action supports Playwright and WebdriverIO frameworks, making it cross-platform and language-agnostic.
July 14, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.95.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linting process, ensuring that code adheres to specified architectural rules and best practices. It uses a file-based substrate for storing lessons, a queryable knowledge index, and an LLM-powered compiler and review commands. The tool helps prevent developers from making common mistakes by enforcing architecture guidelines without relying on AI models, maintaining consistency across projects and improving code quality.
July 14, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v0.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is an action that automates the process of consolidating scattered agent configurations into a single canonical AGENTS.md file, helping to resolve conflicts and ensure consistent configuration across different projects. It also provides guards to prevent future drift in configuration files. The main purpose of AI Harness Doctor is to improve collaboration and reduce errors by providing a unified version control system for agent configurations.
July 14, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and environments, registering a mock server and monitor, committing artifacts to the repository, and running smoke and contract tests. It solves the problem of automating the onboarding process for APIs in GitHub repositories.
July 14, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action automates the creation of a Postman workspace by importing an OpenAPI specification, generating essential collections with contract tests, and enforcing adherence to RFCs and standards. This action simplifies the onboarding process by streamlining the setup of test cases for APIs in one step.
July 14, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of synchronizing Postman collections and environments with a repository. It exports these assets into the repository, wires CI, mock servers, and monitors around them. The action is part of the Postman API Onboarding suite and requires a Postman API key or service token to mint one.
July 14, 2026
PR Risk Analyzer
Version updated for https://github.com/rw-core/pr-risk-analyzer to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Risk Analyzer GitHub Action automates the identification of high-risk changes in pull requests by analyzing files against historical data to identify bug hotspots, code volatility, bus factors, and churn metrics. It provides actionable compound risk predictions such as tribal knowledge risk, defect-injection predictor, and clean-up exception, with evidence-based reporting that cites academic studies and explains why flagged metrics matter directly within the PR comment.
July 14, 2026
PQC Scan
Version updated for https://github.com/sachhg/pqc-scan to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The pqc-scan GitHub Action scans your codebase for quantum-vulnerable cryptography and provides detailed reports on which lines are vulnerable. It automates the process of identifying and migrating to post-quantum algorithms, helping developers stay secure against potential quantum attacks. The tool uses tree-sitter AST parsing to ensure accurate detection without relying on brittle regexes.
July 14, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console CensorChecker is a PowerShell-based script that uses Tcping to batch test and monitor the availability of services, with a focus on detecting network censorship. It can be used for testing TCP latency and monitoring service health in various environments. The tool is designed to help identify potential restrictions or censorship by analyzing response times from target domains.
July 14, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, handling clean URLs, templates, feeds, search, and more. It supports various deployment options including native support for Cloudflare Pages, GitHub Pages, Netlify, Vercel, FTP, and SFTP.
July 14, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight, read-only viewer for OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. The action automates the process of viewing specs, changes, and tasks in an organized manner using OpenSpec data.
July 14, 2026
SFDX Deploy
Version updated for https://github.com/svierk/sfdx-deploy to version v1.2.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sfdx-deploy automates Salesforce metadata deployment and validation. It supports various functionalities including source directories, manifest files, metadata component selectors, test levels, dry runs, delta deployments, and handling destructive changes via the sfdx-git-delta plugin. The action is particularly useful for validating deployments on pull requests or deploying metadata to higher environments efficiently.
July 14, 2026
SFDX Run Tests
Version updated for https://github.com/svierk/sfdx-run-tests to version v1.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Salesforce Apex, LWC (Jest), and Flow tests from a single step, providing comprehensive coverage reports for each type of test. It supports toggling the execution of each test type, highlights coverage in CLI logs, and writes reports to expected paths for integration with quality tools like SonarQube/SonarCloud or Codecov. The action is particularly useful for streamlining the testing process and ensuring consistent code coverage across different Salesforce projects.
July 14, 2026
cargo-oxidate
Version updated for https://github.com/timweri/cargo-oxidate to version v0.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cargo.lock for packages that are too new or too old based on age thresholds and flags them as potential vulnerabilities. It automates security audits by identifying outdated dependencies and suggests updates to downgrade known risks. The action can be used directly from the command line or as a cargo subcommand, with options to exclude certain packages, customize timeout settings, and enable caching for improved performance in CI/CD workflows.
July 14, 2026
New Behavioral Health Practices Weekly
Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action fetches behavioral-health NPIs from the latest CMS weekly file using the New Behavioral Health Practices Weekly actor. It exports these NPIs as clean JSON in a workflow, with options to run it as a free preview or a full edition that charges $9 per event. The action is designed to help organizations monitor and manage behavioral health practices efficiently within their workflows.
July 14, 2026
Website Indexability Gate
Version updated for https://github.com/unitedideas/website-indexability-monitor to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks a production website’s indexability and returns HTTP status, robots meta, X-Robots-Tag, canonical URL, robots.txt policy, and optional synthetic AI crawler responses. If the homepage is noindex, it fails the job. The check is configured with inputs like fail-on-noindex and can also send synthetic requests to simulate crawler behavior.
July 14, 2026
Install Task
Version updated for https://github.com/yk-lab/setup-task to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-task GitHub Action automates the installation of the Task binary onto the PATH, ensuring secure and reliable downloads with checksum verification and host-pinning. It uses authenticated requests by default and retries transient network failures with exponential backoff to handle potential issues during installation. The action is designed to be a drop-in replacement for arduino/setup-task, supporting versioning and architecture customization options while maintaining compatibility with the Node 24 runtime.
July 14, 2026
kempt-fmt
Version updated for https://github.com/ZacSweers/kempt to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A pre-commit-friendly multi-language source formatting pipeline that automates Kotlin, Java, and Rust code formatting, inserts license headers, and normalizes trailing whitespace. It provides a tailored configuration per repository based on detected languages and supports various tool versions and configurations, including optional license header support.
July 14, 2026
LazyCat GitHub Action
Version updated for https://github.com/ca-x/lazycat-github-action to version v1.1.20.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LazyCat GitHub Action checks Docker image versions, updates explicit LazyCat Manifest targets, builds LPK files, creates update pull requests, and attaches validated LPK files to GitHub Releases. It automates the CI/CD process for creating versioned Release publishing workflows to both stores and preserves Go Template Manifests through a repository Skill.
July 14, 2026
Nitro Client Validate
Version updated for https://github.com/ChilliCream/nitro-client-validate to version v16.5.0.
This action is used across all versions by 5 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action validates client operations against the Nitro registry, automating tasks such as ensuring proper authentication and verifying operation validity. It solves problems related to automated testing and validation of client interactions with a Nitro service. Key capabilities include specifying the stage, client ID, API key, and operations file for validation, along with options to control pull request feedback mode through comment or review.
July 14, 2026
IntentGuard PR Alignment Reviewer
Version updated for https://github.com/derrickchiang1024/intentguard to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary IntentGuard automates an AI-driven alignment review of pull requests against linked Linear issues and sprint intentions. It helps ensure that PRs are aligned with the intended product goals, providing clarity on their scope and potential risks. The action uses Anthropic’s Fable 5 to assess whether the PR meets the requirements described in the Linked issue.
July 14, 2026
mcpfold config gate
Version updated for https://github.com/dj-pearson/MCPFold to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of configuring and managing MCP servers, curating toolsets per client and resolving secret references, thus reducing context-window tax and ensuring consistency across clients. It provides a single canonical configuration file that is folded out to each client, minimizing token usage and maintaining security by not hardcoding secrets.
July 14, 2026
GitHub Star Tracker
Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.4.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Star Tracker automates the tracking of star counts across all repositories, generates visually appealing reports with charts and badges, and sends notifications when changes are detected. It integrates with GitHub workflows to keep track of stars, trends, and comparisons efficiently.
July 14, 2026
MyREDAXO Installer Action
Version updated for https://github.com/FriendsOfREDAXO/installer-action to version 1.3.0.
This action is used across all versions by 341 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading a REDAXO AddOn to myREDAXO’s AddOn store whenever a new release is created on GitHub. It requires MyREDAXO credentials stored as secrets, and uses PHP and Composer to manage dependencies. The action enforces validation using MyREDAXO’s API and can be configured with a description, version, and whether to enforce Redaxo addon validation.
July 14, 2026
Validate ProductSpec files
Version updated for https://github.com/gokulrajaram/ProductSpec to version v0.23.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ProductSpec is an open standard and harness that defines what software should build, how it should be completed, and when. It provides a portable way to define intent up front, attach evidence after work starts, and preserve changes when reality disagrees. This action helps teams and agents ensure that their implementations align with the original requirements and provides tools for validating Product Specs and recording work outcomes.
July 14, 2026
Codex Action
Version updated for https://github.com/icoretech/codex-action to version v0.9.19.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the integration of OpenAI Codex into CI/CD workflows by running non-interactively within Docker containers. It solves problems related to accessing OpenAI’s API without manual setup, providing options for both API keys and OAuth/device authentication. The action supports custom preferences through a config.toml file for further customization.
July 14, 2026
Dependency Support Policy
Version updated for https://github.com/isaac-cf-wong/dependency-support-policy-action to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action and CLI tool manage rolling minimum-supported versions for Python projects. It evaluates the Scientific Python SPEC 0 support policy against package release history to raise dependency lower bounds and the requires-python floor accordingly, while preserving existing constraints and comments in pyproject.toml. The action supports both standalone use and integration into workflows, making it a valuable tool for maintaining project dependencies.
July 14, 2026
detect-git-changes-action
Version updated for https://github.com/isaac-cf-wong/detect-git-changes-action to version v0.0.16.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, detect-git-changes-action, automates the detection of changes in a repository compared to a specified base reference. It helps automate tasks like triggering builds or notifications based on changes, and provides options for path filtering to focus only on specific files or directories. This action is lightweight and robust, using git operations locally to perform comparison, ensuring compatibility with repositories that require full history access.
July 14, 2026
jk-publish-test-results
Version updated for https://github.com/jedi-knights/publish-test-results to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing of multi-format test results as a drilldownable per-test check-run in GitHub, allowing users to click through individual tests and annotations directly from the files-changed diff. It supports various input dialects, including JUnit XML and other formats, and is optimized for cold start performance, with typical parsing times under a second.
July 14, 2026
npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
npm-scan is a comprehensive security tool designed to detect advanced attack vectors not caught by traditional tools like npm audit, Snyk, or Socket. It focuses on identifying obfuscated payloads, credential stealers, kernel rootkits, eBPF hooks, memory extraction, GitHub spoofing, and AI-targeted attacks. The action provides 95%+ confidence in detecting these vulnerabilities and significantly reduces the risk of data breaches, regulatory fines, and financial liability.
July 14, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede Static is a comprehensive static analysis tool designed to detect common security flaws such as CWE-639 IDOR. It provides 100% CVE recall across multiple languages and catches authorization flaws that can lead to data breaches. The action automates the scanning of codebases, including generating SARIF reports for GitHub Code Scanning, diff-only scans for pull requests, and interactive HTML reports. It supports offline operation and is fully customizable with built-in rules for specific security vulnerabilities like IDOR.
July 14, 2026
TestivAI Visual Report
Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness-playwright@1.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of capturing and diffing screenshots to detect visual regressions in web applications locally. It helps identify render noise instead of false positives, providing a more reliable report by comparing both pixel changes and DOM structure. The action supports multiple frameworks (Playwright, WebdriverIO) and offers an optional cloud upgrade for additional analysis and team approvals.
July 14, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.23.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automates the process of pulling new Go module releases to a specified proxy cache when tags are created. It supports standard and submodule version tags and allows customization of proxy configuration, import paths, and build settings. The action ensures that your module is immediately available on platforms like pkg.go.dev.
July 14, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action is a comprehensive tool designed to streamline the setup and testing of new APIs in GitHub repositories. It automates the process of creating a workspace, uploading an OpenAPI specification, generating collections for smoke and contract testing, and setting up CI/CD pipelines with JUnit output. The action supports both US and EU data residency options and integrates seamlessly into GitHub workflows to ensure that all aspects of API development are standardized and automated.
July 14, 2026
Postman Onboarding Insights Linking
Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of discovered services from the Postman Insights agent to an existing Postman workspace and git repository after deployment. It solves the problem of ensuring that every service discovered by Insights is properly cataloged, linked with a collection, a repo link, and live telemetry in the API Catalog. The action provides capabilities for setting up prerequisites, specifying inputs such as project name, workspace ID, environment ID, and Postman credentials, and linking services from Insights to the catalog.
July 14, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, wiring CI, mock servers, and monitors around them. It solves problems related to manual collection management by providing a streamlined and automated solution that integrates with Postman’s API onboarding suite. The action supports various sync modes and provides inputs for configuring project details, workspace assets, and authentication tokens.
July 14, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow action reshapes a generated Postman Smoke collection to match a curated flow.yaml and can optionally inject runtime auth (OAuth2 or API keys) via the Postman gateway. It automates the process of integrating new smoke collections with a specific workflow structure, ensuring consistency across projects.
July 14, 2026
Rust PR Diff Analyzer
Version updated for https://github.com/RAprogramm/rust-prod-diff-checker to version v2.0.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of analyzing Rust project Pull Requests (PRs) to enforce size limits. It uses Rust AST analysis to count only meaningful production code changes, ignoring tests, benchmarks, and examples. This helps teams maintain cleaner PRs that are easier to review and maintain. The action supports features like semantic analysis, qualified names, line ranges, per-unit stats, smart classification, analysis scope reports, weighted scoring, flexible limits, PR comments, and multiple output formats including GitHub Actions format, JSON for integration, human-readable text, and markdown comments.
July 14, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.23.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and comparison of new research methods against an existing codebase. It helps teams measure changes by scheduling runs or triggering them on demand, using Anthropic Opus or z.ai’s GLM models as backends. The action supports draft PRs with self-reviews, issues for preflight checks, and branch-only mode for exploration without committing to a single candidate.
July 14, 2026
Console CensorChecker
Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console-CensorChecker 是一个基于 PowerShell 的 Tcping 批量拨测与审查检测脚本,适用于任何平台。它主要用于检查网络中目标主机的延迟情况,并监控服务可用性,旨在帮助用户了解是否有审查设备的存在。该脚本提供了两种安装方式:PowerShell 模块和 GitHub Actions 调用。
What’s Changed Check Check Need Network Censorship
July 14, 2026
Set up Rocq
Version updated for https://github.com/tchajed/setup-rocq to version v1.7.6.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Rocq, a theorem prover, with OPAM (OCaml Package Manager). It supports caching opam dependencies to speed up future builds and allows for customizing the version of Rocq installed through its inputs. Additionally, it provides options to specify additional Opam repositories and files used in cache generation.
July 14, 2026
cowork-harness
Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a test harness designed to reproduce Claude Cowork’s observable runtime contract across various scenarios and CI environments. It automates the testing of skills by simulating the behavior and limitations of the Desktop app without using it directly, allowing for accurate testing in headless environments. The action supports different fidelity tiers that vary in their level of resources required for execution, from a free demo to live tiers that require additional software such as Claude Desktop and a token for real model interactions.
July 14, 2026
ATR Scan
Version updated for https://github.com/Agent-Threat-Rule/agent-threat-rules to version v3.5.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ATR, an open detection rule format for AI agent security threats, provides a vendor-neutral, machine-readable, peer-reviewable rule format that enables easy integration with any conforming engine. It is used in various applications such as security threat detection and malware signatures, making it analogous to Sigma and YARA for SIEM and malware detection, respectively.
July 14, 2026
Cache Go files efficiently
Version updated for https://github.com/capnspacehook/cache-go to version v2.1.1.
This action is used across all versions by 6 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action cache-go helps in efficiently caching Go module and build files. It ensures that cached build files are not invalidated by changes in dependencies and avoids the need to restore a stale cache when a newer version of Go is used. The action uses separate keys for restoring and saving these caches, making it easier to manage different versions and environments.
July 14, 2026
Contrast AI SmartFix
Version updated for https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action to version v1.0.20.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 5 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SmartFix is an AI-powered GitHub Action that automates the remediation of security vulnerabilities identified by Contrast Security. It integrates seamlessly into existing workflows via GitHub Actions, generating Pull Requests (PRs) with proposed fixes. Key benefits include automated remediation, developer-focused PR creation, and accurate vulnerability context. Users can choose from SmartFix’s internal coding agent or integrate with GitHub Copilot or Anthropic’s Claude Code bot for customized vulnerability fixes.
July 14, 2026
mcpfold config gate
Version updated for https://github.com/dj-pearson/MCPFold to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary mcpfold is a CLI that connects every MCP server without incurring the context-window tax by curating toolsets per client. It reduces the number of tokenized tool schema entries by up to 80% and avoids hardcoding secrets by resolving references. The action simplifies configuration management, making it portable across different clients with a single canonical config file.
July 14, 2026
easySFTP
Version updated for https://github.com/eiserv/easySFTP to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action automates secure SFTP file transfers for deploying build output to any SFTP server. It supports fast, secure uploads with options for host key pinning, configurable uploads, delete mode, dry runs, retries, and outputs for monitoring. The action is designed to be simple yet highly customizable, suitable for both small deployments and complex multi-target scenarios.
July 14, 2026
Sieve Security Scan
Version updated for https://github.com/fendora-io/sieve-action to version v1.4.4.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Sieve is a GitHub Action that uses AI-powered security scanning to detect real vulnerabilities in pull requests, with the ability to suppress false positives. The action automatically scans code files and posts relevant comments on PRs, allowing team members to mark findings as either real or false positive. It supports customization via inputs for repo alias and failure behavior during checks.
July 14, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across various Codex, Claude, Gemini, and OpenCode ecosystems for security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata, ensuring compliance with main scanner release train standards. The action supports manual scan, lint, verify, and submit modes, with options to specify plugin directories, execution profiles, output formats, and more.
July 14, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to ensure security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata while staying aligned with the main scanner release train.
July 14, 2026
Alcatraz PII Scan
Version updated for https://github.com/hoophq/alcatraz-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Alcatraz PII Scan GitHub Action detects and reports personal identifiable information (PII) in code, logs, comments, or issues across 12 countries. It uses Alcatraz’s detection engine without any external services or network calls. The action scans PR diffs, log outputs, and comment bodies for PII, annotates the lines, posts a sticky report comment, writes a step summary, and can fail the check until PII is removed or allow-listed.
July 14, 2026
GHAGGA Code Review
Version updated for https://github.com/JNZader/ghagga to version v3.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GHAGGA is a production AI code review system that automates static analysis and multi-agent decision-making processes to improve code quality and maintainability. It uses 17 deterministic tools for detection of known issues before running a large language model (LLM). The tool learns from past reviews, retains context, and supports five orchestration strategies for different review needs.
July 14, 2026
npm-scan
Version updated for https://github.com/lateos-ai/npm-scan to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The npm-scan action detects various types of supply chain threats, including kernel rootkits, memory extraction, and AI-targeted attacks. It provides 95%+ confidence on real campaigns and is 1,875x more cost-effective than traditional tools like npm audit and Snyk.
July 14, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.95.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of software vulnerabilities using Open Source Security Framework (SARIF) format. It integrates with various security tools such as Snyk, Checkmarx, Veracode, and more to scan code repositories, container images, and APIs. The action generates findings in SARIF format, which can be integrated into existing vulnerability management systems or used for compliance reporting.
July 14, 2026
AgentReady Repository Scanner
Version updated for https://github.com/napetrov/agentready to version v0.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentReady is an open-source tool that scans a repository to assess its readiness for AI coding agents, helping teams identify and address potential issues before onboarding autonomous agents. It checks for agent instruction surfaces, repository structure, verification command surfaces, capability surfaces, safety signals, CI workflows, context-efficiency risks, documentation entrypoints, and complements existing checks to provide prioritized improvement plans and stable evidence for CI and enterprise tools.
July 14, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.21.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automates the process of pulling new releases of Go modules into a proxy cache when tags are created. It supports standard and submodule version tags, customizes proxy configuration and import paths, allows for configurable Go versions, and includes features like caching and dependency file support. This ensures that module documentation is immediately available on platforms like pkg.go.dev and enhances the reliability of Go dependencies in projects.
July 14, 2026
Postman Onboarding AWS Spec Discovery
Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using existing AWS credentials. It supports zero-config setup, automatically resolves specs in a repo before calling AWS, and integrates seamlessly with Postman’s onboarding suite. The action uses IAM permissions to detect providers and is designed for use in CI/CD pipelines without requiring a GitHub token.
July 14, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reshapes a generated Postman Smoke collection into a curated flow.yaml, injecting runtime authentication for OAuth2 and API keys. It automates the process of preparing a smoke test collection for deployment, ensuring it matches a specified flow specification and handles credentials securely through Postman’s gateway token. The action is part of the larger Postman API Onboarding suite and integrates with other actions like postman-bootstrap-action and postman-repo-sync-action.
July 14, 2026
action-semver
Version updated for https://github.com/quike/action-semantic-release to version v3.13.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the semantic versioning process of software releases using semantic-release, a tool that follows the SemVer guidelines to update versions and generate changelogs. It solves the problem of managing release processes automatically and ensures consistent versioning across multiple repositories. The action provides capabilities for both open-source projects and containerized applications through different workflows.
July 14, 2026
Writing Style Checker
Version updated for https://github.com/theserverlessdev/wsc to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary WSC is a GitHub Action designed to automate the detection of AI-generated text patterns, including problematic writing styles such as weasel words, passive voice, duplicate words, long sentences, nominalizations, hedging, filler adverbs, and AI-specific constructs. It offers real-time feedback in a web editor, can be accessed via an API, integrated into MCP servers, run as a CLI, and is available as a GitHub Action. WSC helps improve writing quality by identifying and correcting common issues without relying on authorship proof.
July 13, 2026
Nitro OpenAPI Upload
Version updated for https://github.com/ChilliCream/nitro-openapi-upload to version v16.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (f9750d0) Update Nitro CLI to 16.5.0-p.18 (7d03052) Update Nitro CLI to 16.5.0-p.15 (4549360) Update Nitro CLI to 16.5.0-p.14 (7dbe656) Update Nitro CLI to 16.5.0-p.13 (382af64) Update Nitro CLI to 16.5.0-p.12 (4113681) Update Nitro CLI to 16.5.0-p.11 (93b85e4) Update Nitro CLI to 16.5.0-p.10 (fe3b40a) Update Nitro CLI to 16.5.0-p.9 (152ca0e) Update Nitro CLI to 16.5.0-p.8 (d80417a)
July 13, 2026
Nitro OpenAPI Validate
Version updated for https://github.com/ChilliCream/nitro-openapi-validate to version v16.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (74f1bac) Update Nitro CLI to 16.5.0-p.18 (62290b7) Update Nitro CLI to 16.5.0-p.15 (b95aa25) Update Nitro CLI to 16.5.0-p.14 (2fb5557) Update Nitro CLI to 16.5.0-p.13 (cd1e066) Update Nitro CLI to 16.5.0-p.12 (77ff158) Update Nitro CLI to 16.5.0-p.11 (2f0fc69) Update Nitro CLI to 16.5.0-p.10 (2a412d7) Update Nitro CLI to 16.5.0-p.9 (2254fce) Update Nitro CLI to 16.5.0-p.8 (db73650)
July 13, 2026
Nitro Schema Download
Version updated for https://github.com/ChilliCream/nitro-schema-download to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (99e548b) Update Nitro CLI to 16.5.0-p.18 (4675710) Update Nitro CLI to 16.5.0-p.15 (6e863ca) Update Nitro CLI to 16.5.0-p.14 (846f984) Update Nitro CLI to 16.5.0-p.13 (844369e) Update Nitro CLI to 16.5.0-p.12 (f2e6204) Update Nitro CLI to 16.5.0-p.11 (8319e48) Update Nitro CLI to 16.5.0-p.10 (e3e2e92) Update Nitro CLI to 16.5.0-p.9 (588bc3b) Update Nitro CLI to 16.5.0-p.8 (f54d391)
July 13, 2026
Nitro Schema Publish
Version updated for https://github.com/ChilliCream/nitro-schema-publish to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (4414fd9) Update Nitro CLI to 16.5.0-p.18 (f0993a9) Update Nitro CLI to 16.5.0-p.15 (087febf) Update Nitro CLI to 16.5.0-p.14 (1610de2) Update Nitro CLI to 16.5.0-p.13 (feb92af) Update Nitro CLI to 16.5.0-p.12 (7b4bd0d) Update Nitro CLI to 16.5.0-p.11 (0f7117b) Update Nitro CLI to 16.5.0-p.10 (9f878a5) Update Nitro CLI to 16.5.0-p.9 (4937267) Update Nitro CLI to 16.5.0-p.8 (a1601ad)
July 13, 2026
Nitro Schema Upload
Version updated for https://github.com/ChilliCream/nitro-schema-upload to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (bb7d11b) Update Nitro CLI to 16.5.0-p.18 (34cd014) Update Nitro CLI to 16.5.0-p.15 (45f94c1) Update Nitro CLI to 16.5.0-p.14 (f435b0c) Update Nitro CLI to 16.5.0-p.13 (2685fa0) Update Nitro CLI to 16.5.0-p.12 (07e75f9) Update Nitro CLI to 16.5.0-p.11 (ece5bd8) Update Nitro CLI to 16.5.0-p.10 (e88a78f) Update Nitro CLI to 16.5.0-p.9 (3954cde) Update Nitro CLI to 16.5.0-p.8 (fa9e5f4)
July 13, 2026
Nitro Schema Validate
Version updated for https://github.com/ChilliCream/nitro-schema-validate to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (9fb7d32) Update Nitro CLI to 16.5.0-p.18 (d57239a) Update Nitro CLI to 16.5.0-p.15 (fbdf775) Update Nitro CLI to 16.5.0-p.14 (6248f8c) Update Nitro CLI to 16.5.0-p.13 (028ee21) Update Nitro CLI to 16.5.0-p.12 (8dca63a) Update Nitro CLI to 16.5.0-p.11 (7e335e8) Update Nitro CLI to 16.5.0-p.10 (b1e033b) Update Nitro CLI to 16.5.0-p.9 (840eec6) Update Nitro CLI to 16.5.0-p.8 (c3f8884)
July 13, 2026
shadow-audit
Version updated for https://github.com/darkmaster0345/shadow-Audit to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
July 13, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.37.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.
July 13, 2026
cargo-deny
Version updated for https://github.com/EmbarkStudios/cargo-deny-action to version v2.1.0.
This action is used across all versions by 7,901 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed PR#881 refactored the CLI, moving some duplicated options/flags into the root and removing several deprecated options/flags/values. See the PR for a full list of changes. Added PR#879 resolved #873 by adding a new bans.std-replacements lint which checks the graph for crates.io sourced crates that have been partially or fully replaced in std and/or core. Fixed PR#880 resolved #765 by respecting non-default build script paths in manifests. PR#881 resolved #874 by cleaning up the CLI, deduplicating some options/flags that caused bug in the list subcommand.
July 13, 2026
EvoOM Guard
Version updated for https://github.com/EvoRiseKsa/EvoOM-Guard-m to version v3.4.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Fix static pre-gate assurance metadata for v3.4.3 by @EvoRiseKsa in https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/51 Full Changelog: https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.4.2...v3.4.3
July 13, 2026
Fallow - Codebase Intelligence
Version updated for https://github.com/fallow-rs/fallow to version v3.4.2.
This action is used across all versions by 307 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Suppression governance fallow suppressions: a read-only inventory of every active suppression marker, grouped per file with line, kind, level, and reason, plus project totals and a stale count cross-referenced from this run’s findings. Teams governing tech debt (and agents that should distrust a “clean” verdict) no longer grep for fallow-ignore by hand. Ships with --format json (new suppression-inventory envelope) and full workspace/changed/file scoping; always exits 0. MCP tool list_suppressions exposes the same inventory to agents on the MCP surface, returning the JSON envelope verbatim. Every “To suppress:” hint in the human footer now names a token fallow actually parses. Eight sections printed tokens the parser does not recognize, so following the hint suppressed nothing and then surfaced a stale-suppression finding on top. Hint tokens now derive from the issue registry, backed by a roundtrip guard test. Thanks @slyeargin for catching the unused-files case in #1820. Native GitHub workflow output --format github-annotations and --format github-summary: inline PR annotations (::error / ::warning / ::notice workflow commands) and job-summary markdown straight from the CLI, no bundled action required. Both are log-based, so they render on fork PRs without a write token. fallow report --from <results.json>: analyze once with fallow --format json -o results.json, then render annotations and the job summary from the saved envelope, byte-identical to the direct run. Monorepo CI paths Behavior change: CI-facing formats emit repository-root-relative paths when --root is a subdirectory. GitLab’s Code Quality widget matched nothing and inline review discussions were rejected when the analyzed project lived in a package subdirectory, because codeclimate, review-github, and review-gitlab addressed files relative to --root. All CI formats now share one namespace, detected via the git toplevel; pass --report-path-prefix '' to restore the old output. Single-package repositories are unaffected. See docs/backwards-compatibility.md for the classification rationale. --annotations-path-prefix is now --report-path-prefix and governs every CI-facing format; the old name keeps working as an alias. --diff-file resolves the diff’s path namespace from the diff itself, so changed-file filtering works in monorepo packages for both git diff conventions; a diff that parses but touches no analyzable files filters to zero findings, and an unplaceable diff warns and reports at full scope instead of producing a plausible-looking empty report. Renamed files keep their old_path in review-gitlab. Thanks @Jerc92 for the diagnosis and the patch in #1808. unused-class-members accuracy Four extraction gaps produced false positives on dependency-injection-style code, reported across three issues by adopters running the rule on real codebases:
July 13, 2026
GitHub Star Tracker
Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.3.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.22.3 (2026-07-13) Bug Fixes tolerate stargazer page failures and stop swallowing fetch errors (#150) (a302833)
July 13, 2026
GHA Bump Tag
Version updated for https://github.com/gha-actions/bump-tag to version 0.4.0.
This action is used across all versions by 9 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Enable RELEASE_CREATE in bump workflow by @jaynath-d in https://github.com/gha-actions/bump-tag/pull/5 Full Changelog: https://github.com/gha-actions/bump-tag/compare/0.3.0...0.4.0
July 13, 2026
action-ecr-publish
Version updated for https://github.com/heronlabs/action-ecr-publish to version v6.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v6.0.3 (1f89ae4) build(deps): bump the actions group with 2 updates (#27) (1af0aef) [skip ci] bump v6.0.2 (43d9c12) chore: migrate supera.json to 2.x schema (#28) (2a5ab83) [skip ci] bump v6.0.1 (35506d7) chore: update bats-core action to use version 4.0.0 (200cf9e) [skip ci] bump v6.0.0 (08a376d) [skip ci] bump v5.0.7 (b34355d) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (5a45df3) [skip ci] bump v5.0.6 (03a1d51)
July 13, 2026
borderlint AI Data-Residency Lint
Version updated for https://github.com/iolairus/borderlint to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed borderlint init — interactive wizard that scaffolds residency.json: home-base and data-class interview, inventory-grounded jurisdiction walk, overwrite guard (--force), non-interactive --home/--classes for CI. --format badge — shields.io endpoint JSON for READMEs and CI dashboards: green clean, red failures, yellow warn-only, blue inventory; non-gating export.
July 13, 2026
AI Smoke Test
Version updated for https://github.com/JFolberth/ai-smoketest to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update action description for clarity on smoke testing multiple agents by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/5 Update copilot instructions and publishing guidelines for Marketplace… by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/6 docs: rename Azure AI Foundry to Microsoft Foundry by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/7 Full Changelog: https://github.com/JFolberth/ai-smoketest/compare/v1.0...v1.0.1
July 13, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.9.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.3
July 13, 2026
gha-mergify-ci
Version updated for https://github.com/Mergifyio/gha-mergify-ci to version v23.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: expose test_results_upload output for junit-process by @jd in https://github.com/Mergifyio/gha-mergify-ci/pull/257 refactor: install Mergify CLI via Mergifyio/setup-cli action by @sileht in https://github.com/Mergifyio/gha-mergify-ci/pull/263 feat(scopes): add all_scopes input to flag a PR as impacting all scopes by @jd in https://github.com/Mergifyio/gha-mergify- Full Changelog: https://github.com/Mergifyio/gha-mergify-ci/compare/v22...v23
July 13, 2026
AI Harness Doctor
Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v0.13.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(action): propagate wrapper failures by @NieZhuZhu in https://github.com/NieZhuZhu/ai-harness-doctor/pull/89 fix(docs): escape Node badge alt text by @NieZhuZhu in https://github.com/NieZhuZhu/ai-harness-doctor/pull/90 Full Changelog: https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.13.2...v0.13.3
July 13, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.32.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed md032: stop flagging ordered lists nested in MkDocs admonitions (80f896e) md013: recognize sentence boundaries followed by footnote references (04a8c78) md036,md023: skip admonition and content tab bodies under MkDocs flavor (e8d1421) md040: recognize py and py3 as Python language aliases (6e7f8bf) md057: anchor URL extraction so links cannot borrow a sibling’s destination (5a643ca) Performance reflow: skip pulldown-cmark parses when a span kind cannot be present (66d7f7b) Downloads File Platform Checksum rumdl-v0.2.32-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.32-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.32-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.32-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.32-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.32-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.32-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
July 13, 2026
Setup Sema
Version updated for https://github.com/sema-lisp/setup-sema to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only patch: fix the header badge layout on the GitHub Marketplace listing (badges were stacking into a column instead of a row) and absolutize the LICENSE link. No functional changes to the action — identical to v1.0.0 in behavior.
July 13, 2026
pipguard
Version updated for https://github.com/shenxianpeng/pipguard to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐛 Bug fixes Fix scan-feed: resilient per-entry download by @shenxianpeng in #65 Full Changelog: https://github.com/shenxianpeng/pipguard/compare/v0.4.0...v0.4.1
July 13, 2026
Deploy to Vercel
Version updated for https://github.com/Spectra010s/d-vercel to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added prebuilt input option — deploy prebuilt assets using --prebuilt, skipping vercel pull (#4) sticky-comment input option — choose between updating a single sticky PR comment or posting a new one on each change (#3) CONTRIBUTING.md — developer onboarding guide (#8) prettier added to devDependencies for consistent formatting on fresh checkouts (#8) Linked contributing guide in README and updated compiled dist (#11) Removed marker input — internalized as a constant; users no longer need to configure it
July 13, 2026
pinprick-action
Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.3.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Pins pinprick 0.22.0 as the default engine version.
July 13, 2026
graph-sync
Version updated for https://github.com/wordlift/graph-sync to version v6.11.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wordlift/graph-sync/compare/v6.11.4...v6.11.5
July 13, 2026
CCW Extension Deployment
Version updated for https://github.com/BenPaoDeXiaoZhi/ccw-extension-deploy to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary 这个 GitHub Action 主要功能是将 Gandi 扩展文件部署到 CCW 的 OSS,并自动更新项目资产列表中的扩展引用。它还提供了一个简单的步骤指南,帮助用户设置和使用该 Action。
What’s Changed v1.0.1: add dep: teamwork (287a1db) v1.0.0: 支持了协作作品 (1ebcdf9) v0.2.5: 忘了build了… (ad6fc09) v0.2.5: 忽略过时警告 (cb0081e) v0.2.4: 添加警告 (4cda2f9) v0.2.3: update (4117714) v0.2.2: fix gandi maybe undefined (5f812d3) v0.2.1: add dep: jszip (716309f) v0.2.0: bundle with more deps (ba40831) v0.1.1: 增加icon (9adb457)
July 13, 2026
BouncerFox Scan
Version updated for https://github.com/BouncerFox/cli to version v0.9.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BouncerFox CLI is a command-line tool that scans AI agent configuration files for security, quality, and compliance issues. It analyzes files such as .md files containing skill definitions and Claude context, rule configurations, and plugin manifests to identify potential vulnerabilities and best practices. The tool runs entirely offline, ensuring no data leaves the user’s machine, and supports various output formats including JSON and SARIF for integration with IDEs and CI systems.
July 13, 2026
AI Blog Post Generator — roadtrip-blogger
Version updated for https://github.com/cazerme/blog-marketing-skills to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates and optimizes blog posts using the roadtrip-blogger agent, which creates North American road-trip blog posts that are unique and verified. It integrates with Claude’s skills to generate content and ensures that the blog remains SEO-optimized and GEO-focused by checking for duplicates and facts already published. The action can be triggered by a schedule or manually and generates posts in the user’s site’s format, ensuring no duplication and factual accuracy.
July 13, 2026
mcpconform
Version updated for https://github.com/cejor6/mcpconform to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mcpconform GitHub Action is a static linter that checks MCP setup correctness. It validates tool definitions, server manifests, and client configuration files against the MCP spec and provider profiles. The action supports auto-detection of artifact types, target providers, and output formats like SARIF for integration with code scanning tools.
July 13, 2026
.NET Build/Test/Pack/Push
Version updated for https://github.com/f2calv/gha-dotnet-nuget to version v2.1.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds and packages .NET class libraries, pushing them to both the official NuGet feed and GitHub Packages. It automates the process of creating and publishing NuGet packages, including handling versioning, configuration options, and integration with GitHub Packages using a GitHub token or NuGet API key.
July 13, 2026
gha-release-versioning
Version updated for https://github.com/f2calv/gha-release-versioning to version v1.3.7.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates and releases a semantic version of a repository using GitVersion, with options to customize the version and tagging behavior. It automatically detects the required GitVersion configuration file version and handles both v5 and v6 configurations. The action supports generating release notes from merged PRs since the last release.
July 13, 2026
GitHub Star Tracker
Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.2.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Star Tracker is a GitHub Action that tracks the star counts of all repositories across your organization on a schedule. It generates visual reports with animated SVG charts, badges, and markdown/HTML reports to help you monitor repository popularity and growth trends. Key capabilities include automatic dark/light mode support, configurable retention, smart filtering options, stargazer tracking, email notifications, and CSV export for machine-readable data.
July 13, 2026
Setup Flutter SDK
Version updated for https://github.com/flutter-actions/setup-flutter to version v4.3.
This action is used across all versions by 822 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and sets up the Flutter SDK for use in actions by downloading it, adding flutter and dart commands to the path, supporting caching of pub dependencies and the installed SDK, and automating the publishing of packages to Pub.dev. The action takes inputs for specifying a Flutter version, release channel, and cache options.
July 13, 2026
shipready Quality Gate
Version updated for https://github.com/formalness/shipready to version v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
shipready is a CLI tool designed to help developers identify and fix common issues in AI-generated code projects. It scans the project for hardcoded secrets, missing .env.example files, debug logs, unfinished TODOs, and broken repo hygiene. The tool provides an automated way to check and optionally fix these issues before releasing the application. shipready is particularly useful for AI coding tools, as it detects common pitfalls that can be harmful to security and maintainability once deployed.
July 13, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.464.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It identifies security, publishability, runtime readiness, and trust signals in plugins, emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with GitHub Marketplace workflows and supports different execution modes, formats, and reporting options.
July 13, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.464.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The action is designed to handle both local repository content and live network probing for verify mode, providing flexibility for different integration needs.
July 13, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, and other threats across various ecosystems like npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It generates CycloneDX SBOMs with real dependency inventories, verifies SLSA provenance, and correlates findings into attack-chain incidents.
July 13, 2026
borderlint AI Data-Residency Lint
Version updated for https://github.com/iolairus/borderlint to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
borderlint is a static linter designed to scan AI data and model traffic within a repository, evaluating it against residency, sovereignty, and provenance dimensions. It supports multiple programming languages (Python, TypeScript/JavaScript, Java/Kotlin) and can generate reports in various formats such as JSON, SARIF, SBOM, evidence packs, and HTML. The action automatically checks for compliance with predefined policies and provides detailed audit reports to ensure data and model traffic adhere to specified regulations.
July 13, 2026
Aeroflare CI
Version updated for https://github.com/ItzEmoji/aeroflare to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the caching and pushing of Nix build outputs to an OCI registry from CI. It uses the aeroflare tool to generate OCI images with store paths as tags, enabling fast lookups in container registries. This action streamlines the process for developers by handling cache management and OCI image creation automatically.
July 13, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Agent Guard is a deterministic guardrail that blocks AI coding agents from accidentally exposing secrets during tool calls. It uses gitleaks for detection and plain shell scripts for integration. It runs at the agent’s tool boundary to block common secret exposure methods, such as reading .env files or writing sensitive values. Agent Guard pairs with commit/CI scanning for defense in depth. It is not a vault or credential rotator but provides real-time protection before secrets are exposed.
July 13, 2026
pytest Benchmark Baseline Check
Version updated for https://github.com/LennardZuendorf/pytest-bench-action to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates performance benchmarking using pytest-benchmark. It compares test results against per-branch baselines, allowing developers to track and report changes in performance over time. Key features include automatic baseline management, tolerance-based threshold checking, and the ability to override regressions for specific PRs. The action is particularly useful for maintaining consistent performance metrics across different environments and detecting unexpected performance regressions.
July 13, 2026
Dependabit - AI-Powered Dependency Tracker
Version updated for https://github.com/pradeepmouli/dependabit to version @dependabit/utils@0.1.17.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Dependabit is an AI-powered dependency tracking action that automatically discovers, tracks, and monitors external dependencies referenced in a codebase. It uses LLMs to intelligently detect dependencies like GitHub repos, documentation sites, API references, research papers, and more. Dependabit provides features for automatic updates, change monitoring, and flexible configuration, making it a powerful tool for managing software dependencies effectively.
July 13, 2026
ActionScope
Version updated for https://github.com/r12habh/ActionScope to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ActionScope is a GitHub Action that scans your CI/CD workflows to identify and report potential security risks in AWS permissions. It provides plain-English explanations of what your workflows can do if compromised, including actions like role escalation, privilege escalation, and data exfiltration. The action also detects known-compromised actions, OIDC trust policy misconfigurations, script injection, artifact poisoning, AI agent prompt injection surfaces, unpinned actions with SHA resolution, local recursion in reusable workflows, and correlated exposure paths.
July 13, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.49.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines, automating the identification of potential misconfigurations, hardcoded secrets, and other security issues. It offers full offline determinism to ensure consistent findings across different runs, producing auditor-ready compliance-evidence packs including SARIF for GitHub Security tabs.
July 13, 2026
Setup Sema
Version updated for https://github.com/sema-lisp/setup-sema to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sema setup action automates the installation of the Sema Lisp language in GitHub Actions workflows. It supports cross-platform installations, checksum verification, and tool caching to improve performance. The main functionality is to set up the Sema interpreter and provide options for pinning versions and custom download URLs. Users can specify the version they want to use via inputs or rely on default settings from .sema-version or .tool-versions.
July 13, 2026
Sentinel Git Secrets Scanner
Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentinel is a high-performance, zero-dependency Git pre-commit secret scanner and credentials detector written in Go. It automatically blocks accidental commits of sensitive information such as API keys, SSH private keys, and cloud credentials before they enter version control. Sentinel uses a three-tier detection pipeline to efficiently scan for secrets, with support for pattern matching, entropy analysis, and context classification.
July 13, 2026
Skaphos Oiax
Version updated for https://github.com/skaphos/oiax to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action skaphos/oiax@v1 automates the reconciliation of Git branches in a GitOps repository, ensuring that changes are promoted through a defined graph of environments. It validates the promotion graph, plans the actions required to reconcile it, and applies those actions by creating, updating, and closing pull requests between branches. The Action is designed for Linux runners on x64 and ARM64 platforms, with release binaries available for other platforms.
July 13, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight, read-only viewer designed to explore OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. spek turns your local OpenSpec directory into an accessible interface, enabling users to browse specs, changes, and tasks in a hierarchical manner. The action automates the process of aggregating multiple git worktrees into one view, offering a comprehensive overview of project changes and tasks.
July 13, 2026
vibestats
Version updated for https://github.com/stephenleo/vibestats to version v2.4.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeStats is a GitHub Action that tracks and stores Claude Code and Codex session statistics in your private GitHub repo. It provides a live heatmap on your GitHub profile and a full analytics dashboard, allowing you to track historical usage data beyond the default 30-day limit set by Claude Code. The action ensures privacy by storing small JSON aggregates before the cleanup process occurs, making it survive machine wipes and reinstalls.
July 13, 2026
Commit Pet
Version updated for https://github.com/yukurash/commit-pet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Commit Pet is a GitHub Action that visualizes the growth of your commit activity in your GitHub profile README. It generates an SVG pet with three species (slime, cat, ghost) that change mood based on your recent commits and levels up as you contribute more. The action supports customization options like species, name, output file, and theme.
July 13, 2026
Build ZeroPress Pages
Version updated for https://github.com/zeropress-app/zeropress-build-pages to version v0.6.13.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @zeropress/build-pages GitHub Action automates the process of converting Markdown files and public assets into a static ZeroPress site. It performs the following key capabilities:
It builds the static output, suitable for deployment to modern hosting platforms such as GitHub Pages, Cloudflare Pages, Netlify, or Vercel. The generated output consists of plain static files that can be deployed at the origin root of a static hosting provider. Build Pages serves as the Markdown-source document publishing entry point for ZeroPress and is used by other workflows to build from preview-data.json and a theme, or publish after managed authoring workflows in ZeroPress Studio. The action generates preview-data.json, stages public files, and prepares the site data, ultimately providing static HTML pages and assets that can be deployed using a hosting provider’s deployment action.
July 13, 2026
fish-shop/install-plugin
Version updated for https://github.com/fish-shop/install-plugin to version v2.3.114.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 8 updates by @dependabot[bot] in https://github.com/fish-shop/install-plugin/pull/419 Full Changelog: https://github.com/fish-shop/install-plugin/compare/v2.3.113...v2.3.114
July 13, 2026
fish-shop/run-fishtape-tests
Version updated for https://github.com/fish-shop/run-fishtape-tests to version v2.3.114.
This action is used across all versions by 36 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 8 updates by @dependabot[bot] in https://github.com/fish-shop/run-fishtape-tests/pull/406 Full Changelog: https://github.com/fish-shop/run-fishtape-tests/compare/v2.3.113...v2.3.114
July 13, 2026
fish-shop/syntax-check
Version updated for https://github.com/fish-shop/syntax-check to version v2.2.110.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 7 updates by @dependabot[bot] in https://github.com/fish-shop/syntax-check/pull/380 Full Changelog: https://github.com/fish-shop/syntax-check/compare/v2.2.109...v2.2.110
July 13, 2026
shipready Quality Gate
Version updated for https://github.com/formalness/shipready to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Complete secret scanner rewrite: Shannon entropy gate for generic credentials, high/medium confidence levels (errors vs warnings), automatic downgrade in test/fixture paths, 12 new providers (GitLab, DigitalOcean, Hugging Face, Shopify, Mailchimp, Airtable, Fly.io, Cloudflare, Heroku, Discord, webhook URLs, AWS secret keys), repeat/sequence filters, template detection, and bundle guard. 115 tests.
July 13, 2026
forsakringskassan/eslint-config
Version updated for https://github.com/Forsakringskassan/eslint-config to version v15.3.5.
This action is used across all versions by 23 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 15.3.5 (2026-07-12) Bug Fixes deps: update dependency @vitest/eslint-plugin to v1.6.22 (#208) 2d1044d
July 13, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.463.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/58249800fa432261d8ac0afb7a06ab4ca85ebcb1 with plugin-scanner 2.0.1064.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.462...v1.2.463
July 13, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.463.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.463
July 13, 2026
Gemini code review
Version updated for https://github.com/jgunnink/gemini-review-bot to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed New instructions action input — extra review guidance can now be passed directly in the workflow under with:, mirroring how model works. It overrides the instructions key in .github/gemini-review.yml when both are set. (#8, fixes #7) No more hallucinated “this version doesn’t exist” findings — the prompt now forbids flagging version numbers, action tags, dependency versions, or model ids as nonexistent or outdated, since the model can’t verify them against current release info. (#8, fixes #7) Clearer configuration docs — the README now spells out the workflow-inputs vs config-file split (and the near-identical filenames one directory apart), with an inputs table. Note for existing setups If your workflow already had an instructions: key under with:, it was previously ignored with a warning — it now takes effect, and wins over the config file. That’s almost certainly what you intended, but if you have different values in both places, the workflow input is the one that applies.
July 13, 2026
auto-issue-review
Version updated for https://github.com/kldhsh123/auto-issue-review to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/kldhsh123/auto-issue-review/compare/v0.1.0...v0.1.1
July 13, 2026
cargo-rail
Version updated for https://github.com/loadingalias/cargo-rail-action to version v5.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/loadingalias/cargo-rail-action/compare/v5.0.0...v5.1.0
July 13, 2026
LumaTrack Report Run
Version updated for https://github.com/LumaTrack/report-run to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This action reports a workflow run to LumaTrack (https://lumatrack.io) so you can track what your CI/CD automation actually saves you. I built LumaTrack because every automation tool grades its own homework; this is the neutral ledger version, where failures count against you and every number can be traced back to the runs that produced it.
July 13, 2026
Jira Release Link
Version updated for https://github.com/mantasmatij/jira-release-link to version v3.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat!: node24 and other upgrades across the board by @skirsdeda in https://github.com/mantasmatij/jira-release-link/pull/2 New Contributors @skirsdeda made their first contribution in https://github.com/mantasmatij/jira-release-link/pull/2 Full Changelog: https://github.com/mantasmatij/jira-release-link/compare/2...v3.0.0
July 13, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.94.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 13, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.20.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.20 (2026-07-13)
July 13, 2026
PixelVault — Upload Screenshots
Version updated for https://github.com/pixelvault-dev/screenshots-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the PixelVault Upload Screenshots GitHub Action.
Host CI screenshots (visual-regression diffs, Playwright/Cypress failures) on PixelVault and drop them into the pull request — no more digging through zip artifacts.
- uses: pixelvault-dev/screenshots-action@v1 if: failure() with: api-key: ${{ secrets.PIXELVAULT_API_KEY }} path: test-results pattern: "*-diff.png" visibility: private Globs screenshots → uploads into one PixelVault collection via POST /v1/images/batch (chunked, idempotent by collection-name). Private by default → signed URLs; posts a sticky PR comment with a diff table. Zero runtime dependencies (runner Node built-ins only). Reference @v1 for the moving major tag, or @v0.1.0 to pin.
July 13, 2026
Multi-Style Contribution Snake
Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v13.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐍 Multi-Style Snake Daily Update Automated daily release to the GitHub Marketplace.
Version Details:
Tag: v13.07.26 Release Date: $(date +’%A, %B %d, 20%y') Included Features:
5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds) Automated Month Labels above grids Dynamic Username Detection Auto-generated Asset Gallery
July 13, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.20.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fix Pre-PR fidelity gate’s remediation pass now inherits the coding session’s self_review mode context. Under v1.7.19 and earlier, the remediation pass (after _attempt_pre_pr_fidelity_patch applied edits) called _run_pre_pr_fidelity_check without self_review, silently defaulting to Mode 1 with no substitutions or scope-outs. Any Mode-2 refinement that triggered the fidelity gate on the first pass then had its documented substitutions wrongly re-flagged as fabrication on the second pass — hard-to-shift outcome for legitimate Mode-2 diffs.
July 13, 2026
Commit Health Gate
Version updated for https://github.com/rw-core/commit-health-gate to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rolling release; tracks the latest v1.x. Pin to v1.0.0 for immutability.
July 13, 2026
Validate Syscribe Model
Version updated for https://github.com/sjames/syscribe to version v0.31.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: suspect-link detection via content baselines by @sjames in https://github.com/sjames/syscribe/pull/85 feat: release baselines — frozen, git-anchored release snapshots by @sjames in https://github.com/sjames/syscribe/pull/86 Full Changelog: https://github.com/sjames/syscribe/compare/v0...v0.31.0
July 13, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/spekhq/spek to version v1.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed TOC navigation lands on the section you clicked — clicking a table-of-contents entry, or opening a #hash deep link, on a Change or Spec detail page no longer scrolls the target heading behind the sticky header, which made it look like the click had jumped one section too far. The offset is now measured from the header that is actually rendered instead of an assumed 80px, and the entry you clicked is the one the TOC highlights. Schema badge under worktree aggregation — when changes are aggregated across worktrees, each change’s schema is now compared against the default schema of the worktree it actually lives in, rather than the main worktree’s. A change that uses its own worktree’s default no longer shows a badge, and the list and detail views agree on this. Scanning also reads each worktree’s openspec/config.yaml once instead of once per change. Thanks to @nthansen (Norman Hansen) for both.
July 13, 2026
Podcast Generator By Abuzar
Version updated for https://github.com/syedabuzar/podcast-generator to version V1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/syedabuzar/podcast-generator/commits/V1.0
July 13, 2026
Install komac
Version updated for https://github.com/UnownPlain/install-komac to version 1.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Fetch latest version from repository variable Full Changelog: https://github.com/UnownPlain/install-komac/compare/1.3...1.4
July 13, 2026
Setup Vamposer
Version updated for https://github.com/ValaFoundation/vamposer to version v0.7.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes From v0.7.0 to v0.7.1:
[Update] meson version 0.7.1 with support github action (8ec8783) by @JanGalek [Add] example vamposer install to github action (9f72f70) by @JanGalek fixup! [Add] github action (d69d1e0) by @JanGalek fixup! [Add] github action (6ba06c3) by @JanGalek [Update] checkout action version in README example (bf7b552) by @JanGalek [Add] github action (7a4013c) by @JanGalek Full Changelog: https://github.com/ValaFoundation/vamposer/compare/v0.7.0...v0.7.1
July 13, 2026
Symfony Security Auditor
Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.13.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump codecov/codecov-action from 5 to 7 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/82 chore(deps): bump actions/cache from 5 to 6 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/83 chore(deps-dev): update ergebnis/phpunit-agent-reporter requirement from ^0.3 to ^1.0 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/79 ci: drop run-cancelling concurrency by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/84 ci: fix unset secret blocking mutation report by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/85 feat(command): add show-scanned option to audit:run by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/87 feat(infrastructure): source LLM pricing from symfony/models-dev catalog by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/89 ci: tighten PHPStan with stricter opt-in checks by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/92 fix(tests): drop redundant always-false coverage guard by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/94 feat(config): support when env blocks in the config schema by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/93 docs(config): use schema for editor completion by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/95 feat: add standalone executable by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/91 docs(examples): drop prompt_caching from examples by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/96 docs(extending): remaining domain ports by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/97 feat(domain): map vulnerabilities to OWASP Top 10:2025 by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/98 chore(ci): release:bump task and tag-push pin guard by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/101 feat(scan): detect committed secrets in root dotenv files by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/99 feat(pipeline): parse instead of regexes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/104 feat(command): add junit output format by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/100 feat(scan): support API Platform by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/105 feat(pipeline): skip baselined findings before review by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/103 feat(scan): support Symfony UX Live Components by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/106 refactor(prompt): split prompt builders by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/107 fix(scan): stop –since from dropping changed dotfiles by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/108 fix(scan): match DOTALL pre-scan patterns across lines by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/109 feat(scan): detect file-upload vulnerabilities as a dedicated attacker skill by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/118 refactor(domain): extract ProjectFile type classification by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/121 fix(report): strip xml-illegal from junit output by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/110 feat(report): add GitHub Actions annotations output format by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/122 refactor(agent): extract shared structured-collection wiring for chunk/review analyzers by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/124 refactor(pipeline): make DI port defaults non-nullable by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/125 feat(domain): add CWE alongside OWASP mapping by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/127 fix(llm): match status codes as tokens in transient failure classifier by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/111 fix: retry concurrent tool conversations by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/120 fix(scan): redact unquoted secret values in inline config assignments by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/112 fix(rate-limit): reconcile each concurrent acquire against its own estimate by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/113 fix(cache): invalidate attacker cache when code-slicing configuration changes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/114 fix(llm): clamp the rate limiter’s Retry-After pause by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/115 fix(scan): flag non-constant-time signature by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/116 fix(bundle): repair stale escalation attacker wiring by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/117 feat(scan): support Twig extensions by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/119 feat(report): mark baselined findings as suppressed in SARIF output by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/123 feat(command): add audit:diff to compare reports by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/126 test: close mutation-coverage gaps by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/128 test: raise slow-test threshold for bundle boot test to match observed duration by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/129 refactor(command): remove dead code by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/130 fix: harden audit pipeline and correct CWE/OWASP by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/131 chore(deps): bump actions/checkout from 4 to 7 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/132 chore(deps): bump DavidAnson/markdownlint-cli2-action from 23 to 24 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/133 fix: batch of audit-loop hardening fixes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/134 Full Changelog: https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.12.0...1.13.0
July 13, 2026
a2a-lint
Version updated for https://github.com/vivek24290/a2a-lint to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of a2a-lint — conformance tooling for A2A protocol agents. (Supersedes v1.1.0, whose publish pipeline was misconfigured.)
Highlights CLI: a2a-lint <agent-url> --live — validates the agent card against the spec and performs live message/send (and, when the card declares streaming, message/stream SSE) round trips. CI-friendly exit codes: 0 conformant / 1 findings / 2 unreachable. GitHub Action: uses: vivek24290/a2a-lint@v1.1.1 — conformance checks on every push. Playground (Docker): inspect, grade and talk to any A2A agent interactively; shareable permalinks; SSE stream viewer; live conformance badge endpoint. a2a-watch monitor (MVP): register deployed agents, scheduled probes with uptime history, webhook alerts on down/recovered. Install pip install a2a-lint or run the playground: docker compose up --build -d → http://localhost:8090
July 13, 2026
PromptShield AI Security
Version updated for https://github.com/Zero-Harm-AI-LLC/promptshield to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PromptShield AI Security v1.0.6 This release adds optional AI-mode support for zero-harm-ai-detectors while preserving the current default heuristic behavior.
What’s new added ai-mode input to the GitHub Action added --ai-mode flag to the CLI PromptShield now enables AI mode by constructing AIConfig() for zero-harm-ai-detectors when requested default behavior remains unchanged: if ai-mode is not enabled, PromptShield continues to use heuristic mode improved compatibility so existing detector integrations and tests continue to work in default mode Usage GitHub Action:
July 13, 2026
Livvie Code Review
Version updated for https://github.com/4itworks/livvie_code_review to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2 Release Retry empty LLM response bodies; classify retries by HTTP status Stop truncating large patches; skip oversized diffs to preserve line mapping Track failed file fetches and exclude from review Reject files exceeding per-file token budget instead of overflowing batches Remove outer pipeline concurrency wrapper to avoid double-gating Track failed batches separately and build rawFindings only from successes Add string-literal-aware JSON repair and stricter finding validation Half-open circuit breaker single-flight probe Template-literal handling in suggestion balance check Cross-file context truncation with marker token reservation Add configurable inputs: cross-file-budget, safety-margin, circuit-breaker-threshold Require node >=24
July 13, 2026
Data Hogo Security Scan
Version updated for https://github.com/datahogo/datahogo to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of the Data Hogo GitHub Action.
Runs the open-source Data Hogo security scanner on your repository in CI — 300+ checks across JS/TS, Python, Go, Java, PHP, C#, mobile, and Supabase. Everything runs locally in your runner; nothing is uploaded. Findings are uploaded to your repository’s Security tab as SARIF.
July 13, 2026
mcpfold config gate
Version updated for https://github.com/dj-pearson/MCPFold to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(ci): resolve env-drift, docs link, and formatting failures by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/42 Benchmark: add exact per-model token counts + VS Code extension dev harness by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/43 Add E22 code-review findings epic to prd.json by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/44 fix(secrets): pass win32 keychain target out-of-band to kill PowerShell injection (S22.1) by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/45 feat(cli): terminal color + info/update management commands by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/46 feat(cli): terminal color + info/update management commands by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/47 fix(cli): adopt untouched init scaffold on import; add test --timeout by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/48 docs: add VS Code Marketplace badge to README by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/49 Version Packages by @github-actions[bot] in https://github.com/dj-pearson/MCPFold/pull/41 Full Changelog: https://github.com/dj-pearson/MCPFold/compare/v1.0.2...v1.1.0
July 13, 2026
AgentGuard Security Scan
Version updated for https://github.com/dockfixlabs/agentguard to version v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add research paper: 6,173 Security Findings in 10 AI Agent Frameworks by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/15 Fix broken CLI + add main.py by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/16 fix: replace circular benchmark claims with honest language by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/17 v0.8.1: Independent Precision Validation (88%) by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/18 Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.7.0...v0.8.1
July 13, 2026
EvoOM Guard
Version updated for https://github.com/EvoRiseKsa/EvoOM-Guard-m to version v3.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v3.3.1 — close the v3.3.0 fail-open policy interactions (schema 1.7) by @EvoRiseKsa in https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/41 Full Changelog: https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.3.0...v3.3.1
July 13, 2026
fish-shop/install-plugin-manager
Version updated for https://github.com/fish-shop/install-plugin-manager to version v2.3.112.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 7 updates by @dependabot[bot] in https://github.com/fish-shop/install-plugin-manager/pull/382 Full Changelog: https://github.com/fish-shop/install-plugin-manager/compare/v2.3.111...v2.3.112
July 13, 2026
Setup Livreur
Version updated for https://github.com/getlivreur/setup-livreur to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/getlivreur/setup-livreur/compare/v1.0.1...v1.0.2
July 13, 2026
mcpscore — MCP server audit
Version updated for https://github.com/mcp-box/mcpscore-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the mcpscore GitHub Action — Lighthouse for MCP in your CI.
Audit an MCP server on every pull request, fail the build when quality drops below a threshold you set, and get the report as a PR comment.
July 13, 2026
Go - Test Suites
Version updated for https://github.com/mvrahden/go-test to version v1.25.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add blog articles by @mvrahden in https://github.com/mvrahden/go-test/pull/85 improve project documentation by @mvrahden in https://github.com/mvrahden/go-test/pull/86 Add Nil/NotNil assertions with defense-in-depth type guards by @mvrahden in https://github.com/mvrahden/go-test/pull/87 Replace unmaintained YAML dependency by @mvrahden in https://github.com/mvrahden/go-test/pull/89 Resilient Go SDK discovery in VSCode extension by @mvrahden in https://github.com/mvrahden/go-test/pull/88 Surface race detector and panic output that was silently dropped by @mvrahden in https://github.com/mvrahden/go-test/pull/91 Add blog posts: migration guide improvements and “Why Your Go Tests Are Slow” by @mvrahden in https://github.com/mvrahden/go-test/pull/90 Clean up internal duplication and dead code by @mvrahden in https://github.com/mvrahden/go-test/pull/92 Full Changelog: https://github.com/mvrahden/go-test/compare/v1...v1.25.0
July 13, 2026
Docker Compose Cache
Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.17.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/305 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.16...v1.8.17
July 13, 2026
PR Comment - Create & Edit
Version updated for https://github.com/spicyparrot/pr-comment-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.5
July 13, 2026
grype_me
Version updated for https://github.com/TomTonic/grype_me to version v1.3.17-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.3.17-release Source Code Updates Go toolchain updated 1.26.4 → 1.26.5. This release includes two upstream Go security fixes:
CVE-2026-39822 — os.Root symlink escape: on Unix, opening a path ending in / inside an os.Root could follow a symlink to a location outside the root if the final path component was itself a symlink (e.g. root.Open("symlink/") would open symlink even though it points outside the root). CVE-2026-42505 — crypto/tls Encrypted Client Hello (ECH) privacy leak. grype_me does not use os.Root or ECH directly, but the fix ships automatically via the toolchain bump and is recommended for all users building or running this action.
July 12, 2026
OAuthLint
Version updated for https://github.com/Auspeo/oauthlint to version oauthlint@0.10.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Re-pins the bundled rule pack to 0.7.0, so oauthlint scan ships the new NestJS and Fastify rules.
Changed Bundled rule pack updated to oauthlint-rules 0.7.0. Docs: https://oauthlint.dev/docs/cli · Full changelog: https://github.com/Auspeo/oauthlint/compare/oauthlint@0.10.0...oauthlint@0.10.1
July 12, 2026
super-release
Version updated for https://github.com/BowlingX/super-release to version super-release/v1.12.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [1.12.1] - 2026-07-12 🐛 Bug Fixes Reduced binary size; stripped unused features (#32) by @BowlingX in #32 ⚙️ Miscellaneous Tasks Bumped packages 👥 Contributors @BowlingX Full Changelog: https://github.com/BowlingX/super-release/compare/super-release/v1.12.0...super-release/v1.12.1
July 12, 2026
Capawesome Cloud Build Action for GitHub Actions
Version updated for https://github.com/capawesome-team/cloud-build-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#012-2026-07-12
July 12, 2026
Dazbos Gemini Review & Triage
Version updated for https://github.com/derailed-dash/gemini-review-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes Add class docstrings to all structured Pydantic models. Add authentication logging showing which credentials are used for both GitHub API and Google GenAI. Support configurable request timeout via a new timeout action input (defaults to 60s). Clean up legacy typing.List usage to conform to PEP 585 (Python 3.12+).
July 12, 2026
Cloudflare Subpath Deploy
Version updated for https://github.com/dytsou/cloudflare-subpath-deploy to version v1.0.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dytsou/cloudflare-subpath-deploy/compare/v0...v1.0.0
July 12, 2026
402coffee Certify
Version updated for https://github.com/englishdoggy/certify-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Certify your x402 paying agent against 402.coffee in CI. On every push it runs the real conformance test (a real, gasless USDC payment on Base), writes the result to the job summary, and can fail the build if the agent’s risk-score tier drops. Use it as englishdoggy/certify-action@v1 — the README has the full workflow snippet, inputs, outputs, and costs. Every result is a fact observed on-chain; it drives the real payment flow, nothing is faked.
July 12, 2026
LegacyLint Delphi Scan
Version updated for https://github.com/Gert-JanDev/LegacyLint to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Static analysis for Delphi/Pascal that runs in CI and comments findings directly on your pull requests: inline annotations on the changed lines plus a single summary comment, with configurable fail-on gating (error / warning / none).
July 12, 2026
Provenant Scan
Version updated for https://github.com/getprovenant/provenant-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the Provenant GitHub Action — run the Provenant license, copyright, and SBOM scanner in a workflow.
Highlights Scan the checked-out repo (or specific paths) and emit any Provenant output format. Changed-file PR scans via paths-file (feed it git diff --name-only). CI license gating: license-policy + fail-on (error|warning) fails the build on a disallowed license. SARIF output (sarif-file) for pull-request and code-scanning alerts. The action always runs the latest published Provenant release; pin the action with @v1.
July 12, 2026
Temple Scope Guard
Version updated for https://github.com/goweft/temple to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new The dependency check now understands Go. Previous versions only recognized pyproject.toml and requirements.txt, so on this repo — and any other Go repo — max_deps silently went unenforced. temple check now reads go.mod (direct requires only; // indirect doesn’t count). A declared max_deps with no parseable manifest is now a failure, not a silent pass. A check that couldn’t run is not a check that passed. The GitHub Action verifies checksums before running anything. It previously downloaded and executed a release tarball with no integrity check. It now verifies against that release’s checksums.txt and fails if the asset is missing or doesn’t match. The action installs to a scratch directory, not your checkout, and defaults to pinning the exact release version instead of a floating latest. The action’s display name is now “Temple Scope Guard” (Marketplace listing requirement — a bare temple collided with an existing GitHub user). Usage is unchanged: uses: goweft/temple@v0.3.1. Upgrading No breaking changes to the contract format. If your temple.toml declares max_deps and your repo is Go, this release may surface a finding that was previously silent — that’s the fix working as intended.
July 12, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.462.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/065f7c87e69fbdbc8e597047ba05916e6e0d8c18 with plugin-scanner 2.0.1063.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.461...v1.2.462
July 12, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.462.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.462
July 12, 2026
Write .env file from secrets
Version updated for https://github.com/horlakz/secretenv to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add exclusions and safe dotenv warnings
July 12, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.9.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.2
July 12, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.14.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.14
Preserve Query-Row State On Clone And Check Empty Stub Query Rows
Move Cache Root To Dedicated Subdirectory So Sweep Cannot Delete License Key
Format And Parse Dates For Every Locale
July 12, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.16.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new start-from-ref — new workflow input that names a branch/tag/SHA on the target fork. When set, the coding session begins with that ref’s diff already applied to the workspace, so lead-content phrasing like “add tests for X” or “refactor Y” acts on real state instead of being advisory.
July 12, 2026
Kamal Accessories Updater
Version updated for https://github.com/robfrank/kamal-accessories-updater to version v26.7.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Merge pull request #20 from robfrank/dependabot/github_actions/github-actions-e8041ce7a0 (43b1e7b) Bump the github-actions group across 1 directory with 2 updates (db9b6c4) Merge pull request #19 from robfrank/dependabot/github_actions/actions/checkout-7.0.0 (40c1558) Bump actions/checkout from 6.0.3 to 7.0.0 (febf81f) Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group [skip ci] (2132e70) Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group (5d62ccf) Merge pull request #16 from robfrank/dependabot/github_actions/softprops/action-gh-release-3.0.0 (f22259c) Bump softprops/action-gh-release from 2.5.0 to 3.0.0 (58df647) Usage To use this version in your workflows:
July 12, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.31.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added action: install rumdl from GitHub Releases instead of pip (7f69695) Performance reflow: optimize inline code mask calculation using pre-extracted spans (27e5507) Downloads File Platform Checksum rumdl-v0.2.31-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.31-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.31-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.31-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.31-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.31-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.31-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
July 12, 2026
Shieldly — AI-Powered Security Analysis
Version updated for https://github.com/shieldly-io/action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed See https://github.com/shieldly-io/shieldly for full changelog.
July 12, 2026
PR Comment - Create & Edit
Version updated for https://github.com/spicyparrot/pr-comment-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.4
July 12, 2026
Azure Static Web Apps Deploy (small)
Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Deployment token is no longer leaked to the environment by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/7 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.3.0...v1.3.1
July 12, 2026
Package MicroPythonOS App
Version updated for https://github.com/tjorim/mpos-package-mpk to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Deterministic .mpk packaging for MicroPythonOS apps, built with pure-Python zipfile (no zip/find/touch dependency — runs on Linux, macOS, and native Windows runners). Follows the layout and reproducibility recipe from docs.micropythonos.com/apps/bundling-apps: fixed timestamps, sorted entries, stored/uncompressed, app folder first.
July 12, 2026
void sync branch
Version updated for https://github.com/voidmason/branch-sync-action to version v1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump actions/checkout from 6 to 7 in the actions group across 1 directory by @dependabot[bot] in https://github.com/voidmason/branch-sync-action/pull/1 New Contributors @dependabot[bot] made their first contribution in https://github.com/voidmason/branch-sync-action/pull/1 Full Changelog: https://github.com/voidmason/branch-sync-action/commits/v1
July 12, 2026
void rust bump
Version updated for https://github.com/voidmason/bump-release-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/voidmason/bump-release-action/commits/v1
July 12, 2026
YGM Alipay Mini Program Upload
Version updated for https://github.com/YGM-Studio/alipay-miniprogram-upload-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial stable release. Uploads a built Alipay Mini Program with the official minidev SDK, validates the complete development tool identity config, supports experience versions, and removes the temporary identity key after upload.
July 12, 2026
YGM WeChat Mini Program Upload
Version updated for https://github.com/YGM-Studio/wechat-miniprogram-upload-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial stable release. Uploads a built WeChat Mini Program with the official miniprogram-ci SDK, validates inputs, reads the version from package.json, and removes the temporary private key after upload.
July 12, 2026
Install Task
Version updated for https://github.com/yk-lab/setup-task to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: setup-task GitHub Action の初回実装 by @yk-lab in https://github.com/yk-lab/setup-task/pull/6 docs: コミュニティヘルスファイルを追加 by @yk-lab in https://github.com/yk-lab/setup-task/pull/17 docs: README にステータスバッジを追加 by @yk-lab in https://github.com/yk-lab/setup-task/pull/20 build(deps): Bump vite and vitest by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/19 build(deps): Bump esbuild and vitest by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/18 build(deps): Bump actions/setup-node from 4 to 6 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/10 build(deps-dev): Bump @eslint/js from 9.39.4 to 10.0.1 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/15 build(deps-dev): Bump vitest from 2.1.9 to 4.1.9 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/14 build(deps): Bump actions/checkout from 4 to 6 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/11 build(deps-dev): Bump eslint from 9.39.4 to 10.5.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/13 ci: GitHub Actions を SHA ピンに固定 by @yk-lab in https://github.com/yk-lab/setup-task/pull/21 build(deps): Bump the actions-toolkit group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/12 build(deps-dev): Bump @vercel/ncc from 0.38.4 to 0.44.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/16 fix(security): repo-token を core.setSecret でマスクする by @yk-lab in https://github.com/yk-lab/setup-task/pull/24 test: withRetry のユニットテストを追加する by @yk-lab in https://github.com/yk-lab/setup-task/pull/25 test: fetchJson の content-type ガードと createReleaseApi を検証 by @yk-lab in https://github.com/yk-lab/setup-task/pull/26 test: checksum 改ざん検出の統合テストと self-test 強化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/27 ci: Codecov でカバレッジ/テスト結果を OIDC アップロードする by @yk-lab in https://github.com/yk-lab/setup-task/pull/28 test: cache-hit 経路の self-test を追加する by @yk-lab in https://github.com/yk-lab/setup-task/pull/29 fix: レンジ指定で tool-cache を GitHub 解決より優先する by @yk-lab in https://github.com/yk-lab/setup-task/pull/30 chore: パッケージマネージャを npm から pnpm へ移行 by @yk-lab in https://github.com/yk-lab/setup-task/pull/34 build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/31 build(deps-dev): Bump typescript from 5.9.3 to 6.0.3 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/32 build(deps-dev): @types/node を ^24 に揃える by @yk-lab in https://github.com/yk-lab/setup-task/pull/35 chore: dist/ を main から外しリリース時ビルド方式へ by @yk-lab in https://github.com/yk-lab/setup-task/pull/36 ci: Codecov PR コメントを有効化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/46 ci: Codecov PR コメントをカバレッジ変動時のみ表示 by @yk-lab in https://github.com/yk-lab/setup-task/pull/47 docs: TODO.md から完了した #8 を移動 by @yk-lab in https://github.com/yk-lab/setup-task/pull/48 ci: .md のみ変更時は重い CI をスキップしつつ required check を維持 by @yk-lab in https://github.com/yk-lab/setup-task/pull/49 feat: ジョブサマリに導入結果を出力(NFR-5) by @yk-lab in https://github.com/yk-lab/setup-task/pull/50 feat: リトライ回数・間隔を input 化(FR-4) by @yk-lab in https://github.com/yk-lab/setup-task/pull/51 chore: 重複した checksum 改ざんテストを統合(#43) by @yk-lab in https://github.com/yk-lab/setup-task/pull/52 feat: 取得ホスト/リダイレクト先を検証(NFR-1) by @yk-lab in https://github.com/yk-lab/setup-task/pull/53 feat: proxy 環境で全 fetch を proxy 経由にする(#54) by @yk-lab in https://github.com/yk-lab/setup-task/pull/57 docs: テスト規約を stub-fetch unit test の実態に合わせる(#55) by @yk-lab in https://github.com/yk-lab/setup-task/pull/58 ci: paths-filter で root 直下の .md も docs 扱いにする(#59) by @yk-lab in https://github.com/yk-lab/setup-task/pull/60 feat: 取得ボディにサイズ上限とタイムアウトを設ける(#56) by @yk-lab in https://github.com/yk-lab/setup-task/pull/61 test: platform.test.ts を §9 全 os/arch 組合せに拡張(#41) by @yk-lab in https://github.com/yk-lab/setup-task/pull/62 ci: ワークフロー静的解析(actionlint / zizmor)を追加(#23) by @yk-lab in https://github.com/yk-lab/setup-task/pull/68 build(deps): Bump dorny/paths-filter from 3.0.2 to 4.0.1 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/64 chore: ESLint から Biome へ一元化(#45) by @yk-lab in https://github.com/yk-lab/setup-task/pull/70 build(deps): Bump crate-ci/typos from 1.31.1 to 1.47.2 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/63 build(deps): Bump semver from 7.8.4 to 7.8.5 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/67 docs: 移行ガイド拡充 + セキュア路線へポジショニング見直し(#38 / #73) by @yk-lab in https://github.com/yk-lab/setup-task/pull/72 chore: lefthook で pre-push に CI 相当チェックを仕込む(#9) by @yk-lab in https://github.com/yk-lab/setup-task/pull/71 chore: TODO.md を GitHub Issues へのポインタに極小化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/74 build(deps): Bump undici from 6.27.0 to 8.5.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/65 feat: リリース自動化ワークフローを追加(#37) by @yk-lab in https://github.com/yk-lab/setup-task/pull/75 fix: action 名を Marketplace で一意な “Setup go-task” に変更 by @yk-lab in https://github.com/yk-lab/setup-task/pull/76 chore: action 名を “Install Task” に変更(Marketplace 一意性) by @yk-lab in https://github.com/yk-lab/setup-task/pull/77 New Contributors @yk-lab made their first contribution in https://github.com/yk-lab/setup-task/pull/6 @dependabot[bot] made their first contribution in https://github.com/yk-lab/setup-task/pull/19 Full Changelog: https://github.com/yk-lab/setup-task/commits/v1.0.2
July 12, 2026
MCP Admit admission scan
Version updated for https://github.com/aolune/mcp-admit to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed MCP Admit v0.3.0 is the first public release of a static-first, no-exec-by-default admission gate for MCP servers and agent tools.
Highlights Approval-aware admission decisions and explicit approval workflows Static scanning without executing MCP servers Toxic-flow composition detection MCP Registry metadata and supply-chain checks Risk scoring and explainable policy recommendations JSON, Markdown and SARIF reports Inventory, discovery, review packs and GitHub Actions integration Security properties Scanned MCP commands are not executed by default Secret values are redacted from reports Definition and capability drift require renewed approval Explicit approval cannot override deny or quarantine decisions Breaking changes Renamed mcp-guard to mcp-admit Renamed the admission command to decide Migrated schemas and baselines to the mcp-admit.* namespace Install from GitHub pipx install "git+https://github.com/aolune/mcp-admit.git@v0.3.0" Or run without installation:
July 12, 2026
ZeroFS Volume
Version updated for https://github.com/Barre/ZeroFS to version v2.0.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Refactor and harden deterministic simulation tests by @Barre in https://github.com/Barre/ZeroFS/pull/529 Retry transient storage compatibility checks by @Barre in https://github.com/Barre/ZeroFS/pull/530 Make graceful shutdown seal, flush, and close atomically by @Barre in https://github.com/Barre/ZeroFS/pull/535 Add fallocate support to FUSE client by @Barre in https://github.com/Barre/ZeroFS/pull/534 Migrate webui to shared client by @Barre in https://github.com/Barre/ZeroFS/pull/536 Full Changelog: https://github.com/Barre/ZeroFS/compare/v2.0.9...v2.0.10
July 12, 2026
makepkg for ArchLinux - Build and Check
Version updated for https://github.com/bodsch/pkgbuild-action to version v2.0.2.
This action is used across all versions by 3 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/bodsch/pkgbuild-action/compare/v2.0.1...v2.0.2
July 12, 2026
Capawesome Cloud Build Action for GitHub Actions
Version updated for https://github.com/capawesome-team/cloud-build-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#011-2026-07-12
July 12, 2026
Outcome Receipts Verify
Version updated for https://github.com/ChelseaKR/outcome-receipts to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First beta release of the offline-first reporting trust chain.
What ships deterministic SQLite metric computation with a receipt for every figure fail-closed numeric grounding before and after suppression CMS-modeled small-cell and complementary suppression controls mandatory human approval before export funder-readable trace view, machine-readable receipts, sealed bundles, and a hash-chained ledger fail-closed metric-mapping review queue for anonymized schemas English and Spanish report output optional policy-gated Bedrock prose drafting, off by default reusable GitHub Action for receipt-drift verification Start here Run the five-minute synthetic housing demo: https://github.com/ChelseaKR/outcome-receipts/blob/main/docs/TRY_THE_DEMO.md
July 12, 2026
Dazbos Gemini Review & Triage
Version updated for https://github.com/derailed-dash/gemini-review-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🔎 Dazbo’s Gemini Review & Triage Action Automated, Google Gemini-based Pull Request reviews and Issue Triaging for all your GitHub repositories and CI/CD pipelines.
[!IMPORTANT] Migrating from deprecated Gemini tools? This action is built as a direct, drop-in replacement for run-gemini-cli, as well as any workflows previously built on the deprecated Gemini CLI or Gemini Agent Assist products.
July 12, 2026
Fork Shepherd
Version updated for https://github.com/FasterApiWeb/fork-shepherd to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/FasterApiWeb/fork-shepherd/compare/v1...v1.1.1
July 12, 2026
Signal Diff Crawl
Version updated for https://github.com/funkysi1701/signal-diff-action to version v1.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/funkysi1701/signal-diff-action/compare/v1.9...v1.10
July 12, 2026
Poolsim Capacity Gate
Version updated for https://github.com/gregorian-09/poolsim-capacity-gate to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Poolsim Capacity Gate v0.3.0 poolsim-capacity-gate is a GitHub Action for backend teams that want connection-pool sizing checks in CI. It installs poolsim-cli, runs poolsim gate, prints the JSON gate report, and fails the workflow when your configured policy says the current traffic, latency, or pool assumptions are unsafe.
July 12, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.460.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.460
July 12, 2026
auto-issue-review
Version updated for https://github.com/kldhsh123/auto-issue-review to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.0
Full Changelog: https://github.com/kldhsh123/auto-issue-review/commits/v0.1.0
July 12, 2026
Airlock RLS — CI Gate for Supabase
Version updated for https://github.com/mateuszingano/airlock-rls to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The CI gate for Supabase RLS. Fails your build when a table ships without RLS, a policy is permissive (USING (true)), or anon can read/write without scoping — the class of bug scanners miss because they check presence, not logic.
July 12, 2026
Miso PR Review
Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.3.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(github-action): update action misospace/pr-reviewer-action (v2.1.1 → v2.1.2) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/407 fix: omit Linked Issue Context / Evidence Providers headers when empty by @Tanguille in https://github.com/misospace/pr-reviewer-action/pull/410 fix(security): reject artifact symlinks by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/411 fix(impact): avoid awk broken pipe by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/412 New Contributors @Tanguille made their first contribution in https://github.com/misospace/pr-reviewer-action/pull/410 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.1.2...v2.1.3
July 12, 2026
Ansible SecOps Linter
Version updated for https://github.com/semx/ansible-secops-linter to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of ansible-secops-linter — security-focused static analysis for Ansible playbooks and roles.
Checks: disabled TLS/host-key verification, hardcoded credentials, remote-script-to-shell execution, world-writable file modes, disabled package signature checks, and secret-handling tasks missing no_log. Text and SARIF output.
July 12, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.4.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.4.4 Released 2026-07-12.
A capability release that adds the experimental MCP Tasks protocol surface to the Bernstein MCP server, plus release-pipeline hardening.
MCP Tasks extension Long-running runs are now exposed through the experimental MCP Tasks protocol. A task-capable MCP client (Claude Code, Cursor, Cline, and others) can start a run with bernstein_run, receive a CreateTaskResult, and then poll status and retrieve the result asynchronously through the get_task, get_task_result, list_tasks, and cancel_task handlers without holding a blocking session open. The task handle embeds the run’s audit-chain head hash ({task_id}:{head_hash}) so a stateless client can still tie a progress claim back to the signed chain.
July 12, 2026
Publish to BadgeHub
Version updated for https://github.com/tjorim/mpos-badgehub-publish to version v1.0.11.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cleanup, no behavior change. CPython’s `stderr` is always line-buffered/unbuffered by default regardless of tty status — `fail()`’s messages (the ones that mattered while chasing `v1.0.6`-`v1.0.9`’s bugs) never actually needed explicit flushing. `stdout` is what block-buffers when piped to a CI log, and that’s handled globally now via `python3 -u` in `action.yml`’s invocation, rather than `flush=True` hand-added to every individual print call (easy to forget on a new one).
July 12, 2026
Publish to FlatPark
Version updated for https://github.com/flatpark/publish-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Publish to FlatPark 🎉
Add five lines to your release workflow and your Linux users get the Flatpak update the same day you publish a release — no tokens, no manifest, no build infrastructure:
July 12, 2026
Actionlint Setup
Version updated for https://github.com/freerangebytes/setup-actionlint to version v0.1.2.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: add dependabot for the devcontainer dockerfile by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/15 docs: updated readme to discuss the benefits of the action by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/16 Misc updates by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/17 ci: add permissions to workflows by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/18 ci: switch versioning workflow by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/19 ci: switch to relying on version workflow for updates by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/20 ci: fix tag and release action name by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/21 ci: fix version calculation outputs by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/22 build(deps): bump freerangebytes/auto-tag-and-release from 0.2.0 to 0.2.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/23 build(deps-dev): bump @commitlint/config-conventional from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/46 build(deps-dev): bump @commitlint/format from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/44 build(deps-dev): bump conventional-changelog-atom from 5.0.0 to 5.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/40 build(deps): bump freerangebytes/auto-tag-and-release from 0.2.1 to 0.3.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/24 chore(commitlint): fix commitlint so it matches expected format by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/47 build(deps-dev): bump @commitlint/cli from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/45 build(deps): bump actions/github-script from 8 to 9 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/48 build(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 20.5.3 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/50 build(deps-dev): bump @commitlint/cli from 20.5.0 to 20.5.3 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/51 build(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/53 build(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/54 build(deps-dev): bump @commitlint/format from 20.5.0 to 21.0.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/52 build(deps-dev): bump @commitlint/cli from 21.0.1 to 21.0.2 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/58 build(deps-dev): bump @commitlint/config-conventional from 21.0.0 to 21.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/59 build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/65 build(deps): bump ghcr.io/devcontainers/features/docker-in-docker from 2.17.0 to 4.0.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/63 build(deps): bump actions/setup-python from 6 to 6.2.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/64 build(deps): bump devcontainers/base from ubuntu-22.04 to ubuntu-24.04 in /.devcontainer by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/62 build(deps-dev): bump @commitlint/cli from 21.0.2 to 21.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/68 build(deps): bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/66 fix: switch to shas for gha dependencies by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/69 Full Changelog: https://github.com/freerangebytes/setup-actionlint/compare/v0.1.1...v0.1.2
July 12, 2026
RunRight CI Resource Monitor
Version updated for https://github.com/gbudjeakp/run-right to version v1.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Remove Azure provider; RunRight focuses on AWS, GCP, and GitHub-hosted runners
July 12, 2026
Pedant - Lint and Format
Version updated for https://github.com/goeselt/pedant to version v1.4.3.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump the all group with 2 updates by @dependabot[bot] in https://github.com/goeselt/pedant/pull/27 fix: update dependencies by @goeselt in https://github.com/goeselt/pedant/pull/29 Full Changelog: https://github.com/goeselt/pedant/compare/v1.4...v1.4.3
July 12, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.456.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/d7060399ddf8b69773a84973870f5e086227c6b6 with plugin-scanner 2.0.1057.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.455...v1.2.456
July 12, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.456.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.456
July 12, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.86.4.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.4 (2026-07-11) Bug Fixes (generate): stop treating ai@6 raw-text output echo as parsed schema output (dc23936)
July 12, 2026
riskratchet
Version updated for https://github.com/KayhanB21/riskratchet-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bumps the composite delegation to KayhanB21/riskratchet@v0.2.15, which brings TypeScript slices 4–5 (cyclomatic complexity, barrel-aware public surface, and native JSON/SARIF output with token-stable identity groundwork). TypeScript remains informational-only and opt-in; the Python path is unchanged.
This wrapper stays a thin passthrough — action.yml in the main repo is the single source of truth for inputs and behavior.
July 12, 2026
cargo-rail
Version updated for https://github.com/loadingalias/cargo-rail-action to version v5.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/loadingalias/cargo-rail-action/compare/v4...v5.0.0
July 12, 2026
tofu-garnish
Version updated for https://github.com/lowlydba/tofu-garnish to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Make footer cuter with emojis and smaller text by @lowlydba in https://github.com/lowlydba/tofu-garnish/pull/4 Full Changelog: https://github.com/lowlydba/tofu-garnish/compare/v1.0.0...v1.0.1
July 12, 2026
Rust Build, Package and Release Action
Version updated for https://github.com/michaelklishin/rust-build-package-release-action to version v3.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.1.0 (Jul 11, 2026) Bug Fixes test-deb and test-rpm now work in clean distro containers. The action previously failed with cargo: command not found because it always compiled itself from source. It now downloads a prebuilt MUSL-based static binary when no Rust toolchain is present publish-crate with publish-dry-run: true now works on PRs and branch pushes. Previously it tried to validate the ref as a version tag and failed on refs like 14/merge
July 12, 2026
Star History Action
Version updated for https://github.com/narayann7/star-history-action to version v1.0.2.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added font-family input. Set it to any Google Fonts family (for example Patrick Hand) and the renderer downloads that font at run time and applies it to the PNG chart. It reads the font’s real internal name so it matches even when that differs from the family string, and non-Latin families such as Noto Sans SC work. Empty input keeps the bundled Comic Neue with no network call, and any download failure falls back to Comic Neue without failing the run. This affects the PNG only, since GitHub strips @font-face from README-embedded SVGs. Optional watch: types: [started] trigger, documented alongside the cron schedule and workflow_dispatch, so a chart can refresh right after a new star. It supplements the schedule rather than replacing it: watch fires on new stars only, never on unstars, and does not refresh the time axis on quiet days. Compatibility The change-detection signature now includes the requested font, so changing only font-family invalidates the cache and re-renders. As a side effect the signature format changed, so the first run after upgrading regenerates the chart once even when the star count is unchanged. Full changelog: https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md
July 12, 2026
Translink GTFS Schedule to SQLite
Version updated for https://github.com/quackers19/Translink-GTFS-Schedule-Pipeline to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial Release
July 12, 2026
YTMusicDisplayWidget
Version updated for https://github.com/rakshithp7/ytmusic-display-widget to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of YTMusicDisplayWidget — render a YouTube Music ’now playing’ SVG card for your README.
July 12, 2026
RHFest Action
Version updated for https://github.com/RotorHazard/rhfest-action to version v3.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed To receive a notification on new releases, click on Watch > Custom > Releases on the top.
✨ New features #296 feat: Add domain validation @klaasnicolaas 🧰 Maintenance #234 Add extractVersion for Python in renovate.json @klaasnicolaas #237 Fix extractVersion for Python base version in renovate.json @klaasnicolaas #238 Refactor extractVersion for Python dependency in renovate.json @klaasnicolaas ⬆️ Dependency updates 51 changes #235 ⬆️ Update dependency ruff to v0.15.8 @renovate[bot] #241 ⬆️ Lock file maintenance @renovate[bot] #240 ⬆️ Update astral-sh/setup-uv action to v8 @renovate[bot] #242 ⬆️ Update dependency ruff to v0.15.9 @renovate[bot] #243 ⬆️ Update docker/login-action action to v4.1.0 @renovate[bot] #244 ⬆️ Lock file maintenance @renovate[bot] #245 ⬆️ Update dependency ruff to v0.15.10 @renovate[bot] #246 ⬆️ Update release-drafter/release-drafter action to v7.2.0 @renovate[bot] #248 ⬆️ Lock file maintenance @renovate[bot] #247 ⬆️ Update docker/build-push-action action to v7.1.0 @renovate[bot] #249 ⬆️ Lock file maintenance @renovate[bot] #250 ⬆️ Update dependency ruff to v0.15.11 @renovate[bot] #252 ⬆️ Lock file maintenance @renovate[bot] #251 ⬆️ Update astral-sh/setup-uv action to v8.1.0 @renovate[bot] #253 ⬆️ Update dependency pre-commit to v4.6.0 @renovate[bot] #254 ⬆️ Update dependency ruff to v0.15.12 @renovate[bot] #255 ⬆️ Lock file maintenance @renovate[bot] #256 ⬆️ Update release-drafter/release-drafter action to v7.2.1 @renovate[bot] #257 ⬆️ Update klaasnicolaas/action-pr-labels action to v3.1.1 @renovate[bot] #258 ⬆️ Update release-drafter/release-drafter action to v7.3.0 @renovate[bot] #259 ⬆️ Update dependency ruff to v0.15.13 @renovate[bot] #260 ⬆️ Lock file maintenance @renovate[bot] #262 ⬆️ Update docker/build-push-action action to v7.2.0 @renovate[bot] #261 ⬆️ Update dependency ruff to v0.15.14 @renovate[bot] #263 ⬆️ Update docker/login-action action to v4.2.0 @renovate[bot] #264 ⬆️ Update docker/metadata-action action to v6.1.0 @renovate[bot] #265 ⬆️ Update docker/setup-buildx-action action to v4.1.0 @renovate[bot] #266 ⬆️ Update release-drafter/release-drafter action to v7.3.1 @renovate[bot] #267 ⬆️ Update dependency ruff to v0.15.15 @renovate[bot] #268 ⬆️ Update actions/checkout action to v6.0.3 @renovate[bot] #270 ⬆️ Update astral-sh/setup-uv action to v8.2.0 @renovate[bot] #271 ⬆️ Update dependency ruff to v0.15.16 @renovate[bot] #272 ⬆️ Lock file maintenance @renovate[bot] #273 ⬆️ Update dependency ruff to v0.15.17 @renovate[bot] #274 ⬆️ Lock file maintenance @renovate[bot] #275 ⬆️ Update release-drafter/release-drafter action to v7.4.0 @renovate[bot] #276 ⬆️ Update dependency ruff to v0.15.18 @renovate[bot] #278 ⬆️ Lock file maintenance @renovate[bot] #283 ⬆️ Update dependency ruff to v0.15.19 @renovate[bot] #277 ⬆️ Update actions/checkout action to v7 @renovate[bot] #285 ⬆️ Update dependency ruff to v0.15.20 @renovate[bot] #286 ⬆️ Update release-drafter/release-drafter action to v7.5.1 @renovate[bot] #287 ⬆️ Update docker/build-push-action action to v7.3.0 @renovate[bot] #288 ⬆️ Update docker/login-action action to v4.3.0 @renovate[bot] #289 ⬆️ Update docker/metadata-action action to v6.2.0 @renovate[bot] #290 ⬆️ Update docker/setup-buildx-action action to v4.2.0 @renovate[bot] #291 ⬆️ Update astral-sh/setup-uv action to v8.3.0 @renovate[bot] #292 ⬆️ Update docker/login-action action to v4.4.0 @renovate[bot] #293 ⬆️ Update astral-sh/setup-uv action to v8.3.1 @renovate[bot] #294 ⬆️ Update astral-sh/setup-uv action to v8.3.2 @renovate[bot] #295 ⬆️ Update dependency ruff to v0.15.21 @renovate[bot] Full Changelog: https://github.com/RotorHazard/rhfest-action/compare/v3.0.1...v3.1.0
July 12, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.4.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.4.2 Released 2026-07-12.
A patch release on top of v3.4.1. It wires the cost-aware batch and cache policies into the live run loop, runs the adapter conformance suite on a real Windows CI runner, and makes the packaged distribution image verifiable. There are no breaking changes and no configuration migration is required.
July 12, 2026
Ward - Pre-Agent Metadata Scanner
Version updated for https://github.com/Sonofg0tham/ward to version v0.2.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/3 ci(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/5 ci(deps): bump actions/setup-python from 5 to 6 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/1 ci(deps): bump marocchino/sticky-pull-request-comment from 2 to 3 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/7 ci(deps): bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/8 ci(deps): bump actions/checkout from 4 to 7 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/9 New Contributors @dependabot[bot] made their first contribution in https://github.com/Sonofg0tham/ward/pull/3 Full Changelog: https://github.com/Sonofg0tham/ward/compare/v0.2.2...v0.2.3
July 12, 2026
Build Apache Maven Dependency
Version updated for https://github.com/sualeh/build-maven-dependency to version v1.0.9.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Action to Build a Maven Dependency v1.0.9 release at last commit abcce43ccf66f696fd5417516cf9449a29f32411
What’s Changed Bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in https://github.com/sualeh/build-maven-dependency/pull/1 Bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/sualeh/build-maven-dependency/pull/2 New Contributors @dependabot[bot] made their first contribution in https://github.com/sualeh/build-maven-dependency/pull/1 Full Changelog: https://github.com/sualeh/build-maven-dependency/compare/v1.0.8...v1.0.9
July 12, 2026
Setup DepVault CLI
Version updated for https://github.com/suxrobGM/depvault to version cli/v1.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Stored credentials (~/.depvault/credentials.json) are now encrypted at rest — DPAPI on Windows, an owner-only AES-GCM key file on POSIX — instead of plaintext. You must sign in again after upgrading: plaintext credential files are no longer migrated, and the server-side session cutover requires a fresh login regardless Fix long-lived sessions dropping to the auth-error panel on a second token expiry: token refresh is now attempted once per request (not once per process) and re-reads credentials from disk first, so a rotation performed by a concurrent request or another depvault process is picked up instead of tripping the server’s replay detection. CI-token 401s are returned as-is, since CI tokens aren’t refreshable login now flows straight into the vault unlock prompt, so push/pull work without a second command logout now revokes the refresh session server-side before clearing local credentials whoami shows the auth panel when the session has expired, instead of a generic failure Fix signing in with GitHub from a CLI login link leaving the CLI polling forever — the OAuth round-trip now carries the device code back (server-side fix; no CLI upgrade needed)
July 12, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.85.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.3 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.3 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.3 GitHub Action:
July 12, 2026
MCP Test Harness
Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Product website: integrations widget, features deck, visual gallery, README badge row. Website naming in user copy. All 18 PyPI packages and GHCR Docker at 3.0.7.
July 12, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.711.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.711.2 Released 2026-07-11
This release of the vg command-line scanner introduces enhanced vulnerability detection and performance improvements. The documentation has also been updated for easier navigation to relevant resources.
What changed New vg scan now checks whether the vulnerable code in your dependencies is actually used, tagging findings as reachable, potentially reachable, not reached, or unknown. Improved The CLI’s public documentation now includes direct links to relevant vibgrate.com pages for easier access to full references. Performance Hosted library docs answers are now cached locally for a day, allowing for instant responses to repeat vg lib and AI-context lookups. Benchmarks Two-arm benchmark of this release against 2026.711.1, interleaved on one runner against the pinned corpus (157 metrics compared).
July 12, 2026
VICE Security Audit
Version updated for https://github.com/Webba-Creative-Technologies/vice to version v3.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary VICE 3.3.0 strengthens remote and local audits with stricter scope controls, safer probes, clearer evidence and more reliable reports.
This release keeps the existing CLI commands, runScan API, scan profiles and GitHub Action inputs compatible.
July 11, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.448.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/992e636d4bf312a3b4cdae1fc03a7ffc2eae478f with plugin-scanner 2.0.1049.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.447...v1.2.448
July 11, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.448.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.448
July 11, 2026
Mirror to BitBucket GitHub Action
Version updated for https://github.com/heussd/mirror-to-bitbucket-github-action to version v3.
This action is used across all versions by 96 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/heussd/mirror-to-bitbucket-github-action/compare/v2...v3
July 11, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.12.0 (2026-07-11) Issue #54 hardening: oversized-file transparency + threat-intel indicator contract
Implements both hardening gaps tracked in issue #54 (follow-up to the merged PR #55 extraction/IOC hardening), plus the dependency maintenance merged this cycle (docker/login-action 4.4.0, vitest + @vitest/coverage-v8 4.1.10). This minor also carries PR #55’s archive-extraction and self-scan-suppression fix to npm (it landed after v5.11.1 was published).
July 11, 2026
Hosho Prompt Reviewer
Version updated for https://github.com/HOSHO-AI/Hosho-prompt-optimization-public to version v1.41.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Taxonomy restructure — Provider-fit moves to Guidance, safety sub-factor retired Mirrors the API taxonomy change (API #175). The PR-comment renderer’s hardcoded taxonomy is load-bearing for the 4-macro score table, so it moves in lockstep:
July 11, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.6
July 11, 2026
Dependency Support Policy
Version updated for https://github.com/isaac-cf-wong/dependency-support-policy-action to version v0.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.1 - 2026-07-11 🐛 Bug Fixes Shorten action description for Marketplace listing (#18) - (1297dd8) Compute TestPyPI publish version fresh via hatch (#19) - (4f9ff16) Point the floating major tag at the release commit (#22) - (f6fc6d3) ⚙️ Miscellaneous Tasks (deps) Update dependency hatch to >=1.17.1 (#20) - (39b7c79) (deps) Update pre-commit hook rbubley/mirrors-prettier to v3.9.5 (#21) - (9a317cd) Contributing: Contributions are welcome! See the Contributing Guide.
July 11, 2026
Actions Breakage Radar
Version updated for https://github.com/jackwalkerlabs/actions-breakage-radar to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Parser compatibility patch for valid GitHub Actions YAML forms.
Supports bare-dash step mappings where uses appears on the following line Supports quoted jobs, steps, runs-on, and uses keys Adds non-null repository and branch report-output coverage 34 tests pass; live 3-repository validation remains 12 workflows and 23 migration warnings with zero failures Use the stable major tag: jackwalkerlabs/actions-breakage-radar@v1
July 11, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.86.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.3 (2026-07-11) Bug Fixes (deps): declare js-yaml + fast-xml-parser as runtime dependencies (48f54d5)
July 11, 2026
L10n.dev AI Localization Automation
Version updated for https://github.com/l10n-dev/ai-l10n to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Added client option to identify integrations of the l10n.dev localization platform. SDK:
Added authOptions as an optional arg to the translate method of AITranslator class. Add client to identify client’s usage correctly Moved apiKey to the authOptions. Breaking changes Optional apiKey arg now in the authOptions CORE:
July 11, 2026
SkillCI Audit
Version updated for https://github.com/LM20230311/skillci to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Phase 3 complete\n\n- Add strict Node behavior-trace assertions for commands, file reads, file writes, and network API attempts.\n- Fail behavior cases on undeclared observed commands or file activity.\n- Keep Docker network denial and constrained fixture isolation in place.\n- Publish npm automatically through GitHub OIDC trusted publishing.
July 11, 2026
Selvedge Coverage Check
Version updated for https://github.com/masondelan/selvedge to version v0.3.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed docs(roadmap): capture the reason-vs-name keying convergence (cowork-os) docs: state the git-import identity boundary + plan the provenance/trust-tier follow-up docs(release): v0.3.9.1 — the dev.to feedback release fix: post-review hardening for the v0.3.9.1 features feat(semantic): optional fuzzy recall — prior_attempts survives renames feat(import): git-history backfill — pre-Selvedge reverts become first-class records feat(hook): PreToolUse enforcement hook — the prior_attempts check becomes deterministic feat(supersede): decision states + supersede flow — reverted is no longer a permanent ban gitignore: keep LLMO mention-share scoreboard local-only build(docker): add Dockerfile for the Docker MCP Catalog submission build(deps): bump actions/setup-python from 5 to 6 build(deps): bump actions/checkout from 4 to 7 chore(gitignore): keep docs/growth-master-plan.md local-only docs(readme): remove broken editor install badges docs: correct phase markers — HTTP + auth ships in v0.4.1, not v0.4.0 docs(architecture): make the Phase 3.2 heading paren-last so notion-sync parses it fix(notion-sync): bump LATEST_SHIPPED to 0.3.9 so the Roadmap mirror marks v0.3.9 phases Done docs(architecture): reconcile v0.3.9 phase plan — Agent Trace export shipped, dev-ergonomics deferred to v0.3.16 docs(manifest): note agent-trace export in the bundle/listing description docs: pin the Coverage Check action example to @v0.3.9 fix(action): trim Marketplace description under the 125-char limit Install: pip install selvedge==0.3.9.1 PyPI: https://pypi.org/project/selvedge/ Docs: https://github.com/masondelan/selvedge/blob/main/docs/getting-started.md
July 11, 2026
Star History Action
Version updated for https://github.com/narayann7/star-history-action to version v1.0.1.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Makes the star history chart render on GitHub and on package registries (npm, pub.dev), and stops external image URLs from 404ing.
Added PNG output. The renderer rasterizes a star-history.png alongside the SVGs, so the chart shows on registries that cannot render SVG (npm, pub.dev). readme-format input (picture or png). picture keeps the SVG <picture> block with GitHub dark/light support; png writes a plain-markdown image at an absolute raw.githubusercontent.com URL, the only form that renders on npm and pub.dev. Changed Stable filenames. Charts are written to fixed paths (star-history-<theme>.svg, star-history.png) and overwritten in place instead of timestamped names. A frozen README URL on a registry no longer 404s when a new chart is generated. This action’s own repository now demos with a static placeholder and no longer commits its live chart into git. Fixed PNG rasterization stripped the decorative feTurbulence/feDisplacementMap sketch filter, which crashed the raster engine (resvg). The SVG output keeps the filter; only the PNG drops it. Compatibility Repositories upgrading from 1.0.0 keep their old timestamped files, so any already published registry README that points at the old URL still resolves. The action stops producing timestamped names but does not delete existing ones. On the first run after upgrade, the chart is regenerated even when the star count is unchanged, so the new stable files and the PNG are created once. Full CHANGELOG: https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md
July 11, 2026
Setup Nimbus
Version updated for https://github.com/nimbus-solution/setup-nimbus to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Resolve latest via release redirect, not the rate-limited API (fcc9f53) Fix curl SIGPIPE (exit 23) when resolving the latest version (c54c8ac) Retry transient download failures on hosted runners (ec9659c) setup-nimbus v1.0.0 — install the Nimbus CLI in GitHub Actions (330632a)
July 11, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.13.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.13
Parse Text Arguments In TIMEVALUE Formula Function
Match Salesforce Errors For emptyRecycleBin, Savepoints, And convertLead
Renew Expired CI Licenses To Support Monthly Subscriptions
Fix EntityParticle And FieldDefinition Metadata
July 11, 2026
Agnostic Code Metrics
Version updated for https://github.com/rw-core/agnostic-code-metrics to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rolling release; tracks the latest v1.x. Pin to v1.0.5 for immutability.
July 11, 2026
sec-recon SBOM gate
Version updated for https://github.com/Shurtug4l/sec-recon-agent to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Publishes the sec-recon SBOM gate to the GitHub Marketplace.
No behavioural change to the gate since v0.1.0. This release trims the action.yml description under the Marketplace 125-character limit and folds in the dependency-lockfile security patches (aiohttp, cryptography, joserfc, pyjwt, python-multipart, starlette, pydantic-ai, js-yaml).
July 11, 2026
Harnessie Verify
Version updated for https://github.com/snapsynapse/harnessie-verify-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release. Adopted via a recorded, human-arbitrated decision: AIDR-0007.
Treat a pull request’s description as claims, not evidence. This action runs your deterministic checks sandboxed (exit codes only), then a fresh-context verifier model that never sees the author’s narrative tests each remaining claim against the actual artifacts, and the job’s exit code gates the merge.
July 11, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.8.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.8 (2026-07-11) Features config: configure main comment presentation (#56) (3c9de80) This PR was generated with Release Please. See documentation.
July 11, 2026
Normalize Major Version Tag
Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.0.9
1.0.9 (2026-07-11) 🐛 Bug Fixes add checkov comments to publish inputs; removed unnecessary inputs from main ci (9a5334d)
July 11, 2026
Graveyard Check
Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of graveyard-check — a CLI that scans your npm lockfile, flags dependencies that are effectively abandoned, and recommends verified community- maintained successors.
What it does graveyard-check scan — scans your package-lock.json, flags likely-abandoned or at-risk dependencies with evidence (last release/commit age, npm deprecation flag, issue response rate), and suggests a maintained successor where one exists graveyard-check check <package> — single-package lookup, no lockfile required --json output and a GitHub Action wrapper for CI integration Seed dataset Ships with 9 researched successor records covering well-known npm abandonment cases: request, node-sass, moment, request-promise, istanbul, gulp-util, colors, faker, and tslint. Every record is backed by verified evidence, not guesses — see data/successors/SCHEMA.md.
July 11, 2026
Install bashunit
Version updated for https://github.com/TypedDevs/bashunit to version 0.41.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ Improvements --retry <n> / BASHUNIT_RETRY re-runs a failed test up to N times; passes if any attempt passes, annotates retried tests, and works with --parallel and --stop-on-failure (#737) --random-order with --seed <n> / BASHUNIT_SEED randomizes test file and function order to surface inter-test coupling; prints the seed for reproducible replay and works with --parallel (#738) --shard <index>/<total> runs a deterministic, non-overlapping subset of the test files to split a suite across parallel CI runners; composes with --parallel (#739) --report-tap <file> writes a TAP v13 report to a file (complements the streaming --output tap) (#740) --report-json <file> writes results as JSON (summary counts + per-test records); no jq dependency (#741) assert_file_permissions <mode> <file> asserts a file’s octal permission mode; portable across GNU/BSD stat (#742) assert_array_length <n> <array> asserts an array has exactly n elements (#743) assert_within_delta <expected> <actual> <delta> asserts a number is within a tolerance; supports floats (#744) 🐛 Bug Fixes watch subcommand failed with bashunit::watch::run: command not found in the released binary because src/watch.sh was missing from the build; it is now bundled (#735) 🛠️ Changes Faster test execution by removing subprocess forks from hot paths (no behaviour change) 👥 Contributors @Chemaclass Checksum SHA256: 146c9b1f5462633d40c377ab0548bbd1a720ce365f49ef6942621192b4d15f79
July 11, 2026
MCP Test Harness
Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Pages PyPI stats bar fix, SPONSORS.md, all 18 PyPI packages and GHCR Docker at 3.0.6.
July 11, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.711.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.711.1 Released 2026-07-11
This release of the Vibgrate CLI includes the addition of documentation related to the scoring methodology. Users can now access the public scoring specification, the risk and drift scoring whitepaper, and shared legal notes directly from the repository.
July 11, 2026
Premature Contribution Firewall dry-run
Version updated for https://github.com/VrtxOmega/premature-contribution-firewall to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PCF v0.1.3 adds impact-first serious candidate scouting and hardens the authority boundaries that keep automation advisory.
Highlights Added broad, read-only serious candidate scouting with explicit collection-integrity and open-PR-overlap gates. Expanded the adversarial residue corpus from 15 to 29 cases covering Unicode/control-text evasion, overlap ownership, repository-context vacuum, lane-gate omission, repro laundering, malformed MCP frames, and malformed batch inputs. Made repository context, lane persistence, repro evidence, and MCP framing fail closed when evidence is missing or malformed. Published through GitHub OIDC trusted publishing with npm provenance; no reusable npm token was required. Verification Tests: 242/242 Deterministic benchmark: 77/77 Adversarial red test: 29/29 Maintainer demo: PASS, replay stable, 0 regressions MCP smoke: PASS npm package dry run: PASS, 75 files Clean registry install: PASS for pcf and pcf-mcp Installed MCP surface: 25 tools, serious scout present, GitHub writes disabled Main verification: https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156257898
July 11, 2026
Diviqra Guard LLM Prompt Scanner
Version updated for https://github.com/diviqra-builds/guard-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Diviqra Guard — GitHub Action v1.0.0 Scan LLM prompts for injection attacks before deployment.
Usage - name: Guard Prompt Scan uses: diviqra-builds/guard-action@v1 with: api_key: ${{ secrets.GUARD_API_KEY }} scan_path: ./prompts/ fail_on: block What’s new Scans .txt/.json/.yaml/.yml/.md prompt files Detects prompt injection, jailbreaks, PII leakage Hindi/Hinglish/Tamil/Telugu/Kannada support Colored summary table in Actions log Configurable fail threshold (block/warn/never) LangChain, OpenAI, FastAPI integrations included Get free API key: https://guard.diviqra.com/register
July 11, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.35.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.
July 11, 2026
trimja action
Version updated for https://github.com/elliotgoodrich/trimja-action to version v1.8.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump undici from 6.26.0 to 6.27.0 by @dependabot[bot] in https://github.com/elliotgoodrich/trimja-action/pull/32 Improve logging by @elliotgoodrich in https://github.com/elliotgoodrich/trimja-action/pull/33 New Contributors @dependabot[bot] made their first contribution in https://github.com/elliotgoodrich/trimja-action/pull/32 Full Changelog: https://github.com/elliotgoodrich/trimja-action/compare/v1...v1.8.0
July 11, 2026
Setup Malbolge
Version updated for https://github.com/fabasoad/setup-malbolge-action to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-malbolge-action/pull/16 fix: issue found by markdownlint by @fabasoad in https://github.com/fabasoad/setup-malbolge-action/pull/17 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-malbolge-action/pull/18 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-malbolge-action/pull/19 Full Changelog: https://github.com/fabasoad/setup-malbolge-action/compare/v0.2.0...v0.2.1
July 11, 2026
GitHub Action for Python based Firebase projects
Version updated for https://github.com/gannonk08/firebase-action-python to version v15.23.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bump firebase-tools to v15.23.0
July 11, 2026
Vizb Action
Version updated for https://github.com/goptics/vizb to version v0.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(line): add –smooth flag for 2D line charts by @hfl0506 in https://github.com/goptics/vizb/pull/187 feat(stats): add multi-select descriptive column picker by @hfl0506 in https://github.com/goptics/vizb/pull/191 feat(bar): add –horizontal flag for 2D grouped bar charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/190 feat(bar/line): add –stack for 2d charts by @hfl0506 in https://github.com/goptics/vizb/pull/194 fix: clear grouped 3D z-axis name under option merge by @ahfoysal in https://github.com/goptics/vizb/pull/192 feat(ci): untrack vizb-ui.gen.go and generate embed in CI by @fahimfaisaal in https://github.com/goptics/vizb/pull/197 feat: add –theme color palette support by @ahfoysal in https://github.com/goptics/vizb/pull/195 New Contributors @hfl0506 made their first contribution in https://github.com/goptics/vizb/pull/187 @ahfoysal made their first contribution in https://github.com/goptics/vizb/pull/192 Full Changelog: https://github.com/goptics/vizb/compare/v0.14.1...v0.15.0
July 11, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.437.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/3049ba4a2fd13a42906f6745178ece5f65f4beb1 with plugin-scanner 2.0.1038.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.436...v1.2.437
July 11, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.437.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.437
July 11, 2026
helmfile-action
Version updated for https://github.com/helmfile/helmfile-action to version v2.4.7.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump @types/node from 26.0.0 to 26.0.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/727 build(deps-dev): bump prettier from 3.8.4 to 3.9.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/728 build(deps-dev): bump eslint-plugin-jest from 29.15.2 to 29.15.3 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/729 build(deps-dev): bump eslint-plugin-jest from 29.15.3 to 29.15.4 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/733 build(deps-dev): bump @vercel/ncc from 0.44.0 to 0.44.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/734 build(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/735 build(deps-dev): bump prettier from 3.9.1 to 3.9.4 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/731 build(deps-dev): bump @typescript-eslint/parser from 8.62.0 to 8.62.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/730 build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.0 to 8.62.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/732 build(deps-dev): bump @typescript-eslint/parser from 8.62.1 to 8.63.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/736 build(deps-dev): bump eslint-plugin-github from 6.0.0 to 6.1.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/738 build(deps-dev): bump @types/node from 26.1.0 to 26.1.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/739 build(deps-dev): bump typescript from 6.0.3 to 7.0.2 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/740 build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.1 to 8.63.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/737 Full Changelog: https://github.com/helmfile/helmfile-action/compare/v2.4.6...v2.4.7
July 11, 2026
Hyperlocalise CI
Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.24.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(web): localize app shell UI with react-intl by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1360 fix(web): show skeleton while side-by-side translations load by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1361 feat(cat): add Find context to side-by-side intelligence panel by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1364 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1363 feat(web): support image upload, agent localize, sync, and CAT by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1365 feat(web): add app shell plan footer by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1362 feat(web): stream inbox agent tool calls and text by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1366 ⚡ Bolt: optimize PHP array parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1369 test(web): cover image localization guards by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1368 feat(cat): treat-as-image and upload for external TMS URL strings by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1367 feat(web): fail db:migrate on duplicate migration numbers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1372 fix(crowdin): add missing concepts field to Glossary model by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1373 fix(web): critical regressions in image jobs, inbox agent parts, and side-by-side CAT by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1370 fix(inbox): strip markdown from conversation list previews by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1374 fix(inbox): prevent stream crash from undefined tool code blocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1375 fix(inbox): simplify tool call UI and scroll button contrast by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1376 feat(app-shell): persistent MobX chat dock with conversation tabs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1377 feat: use gpt-5.6-luna instead of gpt-5.4-mini by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1378 fix(web): refine floating chat dock by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1379 fix(web): improve CAT loading and file menu actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1380 fix(markdown): preserve link delimiters during translation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1382 fix(billing): track Translation jobs and Agent runs meters correctly by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1383 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1384 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.24
July 11, 2026
Jentic API Scorecard
Version updated for https://github.com/jentic/jentic-api-scorecard to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.10.0 (2026-07-11) Bug Fixes extract-docs: rewrite improve-skill cross-link on extraction (97bb1d6) extract-docs: rewrite requirements anchor in improve-skill (1f02432) score: make engine tokenUsage opt-in via –report-token-usage (c542268), closes #284 scripts: derive benchmark metrics from raw scorecards (b623161), closes #284 scripts: exercise proxy self-check + real plumbing in dry-run (a84aa55), closes #284 scripts: match raw scorecards by content, not exact name (c9c15c4), closes #284 skill: guard jentic-api-improve against shipping regressions (b301395), closes #284 skills: make token-usage.json opt-in on explicit request (d0382ea), closes #284 Features cli: add hidden –report-token-usage flag (dfad477), closes #284 scripts: add benchmark results data-file sample fixture (0b1a3be), closes #284 scripts: add improve-benchmark matrix driver + dry-run (ffd3750), closes #284 scripts: add token-counting proxy for engine LLM spend (d7c3890), closes #284 scripts: benchmark 6 default specs, –specs, output dir (1a42db1), closes #284 scripts: capture + render score before/after + iters (c210984), closes #284 scripts: implement real benchmark measurement run (be3ded4), closes #284 scripts: render benchmark doc from results data file (cc3ed72), closes #284 scripts: request engine token usage in benchmark prompt (4aaceb5), closes #284 scripts: sample benchmark cells N times, report median + range (d480d69), closes #284 skills: emit benchmark-summary.json with run outcome (7ae3dae), closes #284 skills: emit token-usage.json from engine tokenUsage (2424387), closes #284 Performance Improvements scripts: run benchmark samples concurrently, isolated per cwd (30df98d), closes #284
July 11, 2026
E2E Self-Heal
Version updated for https://github.com/Lee-Dongwook/E2E-Self-Heal to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Diff parsing rewritten on a tree-sitter AST: the JSX/TSX diff analyzer now walks the parsed syntax tree instead of matching regexes, producing more accurate and robust before/after DOM node extraction. Added tree-sitter dependencies and expanded diff-analyzer test coverage. (#8) Full Changelog: https://github.com/Lee-Dongwook/E2E-Self-Heal/compare/v0.2.2...v0.3.0
July 11, 2026
SkillCI Audit
Version updated for https://github.com/LM20230311/skillci to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Publish the skillci CLI to npm for local development and non-GitHub CI usage. Add npm installation, one-off npx usage, and npm badges to both README languages. Install npm install --save-dev skillci npx skillci audit .github/skills Use LM20230311/skillci@v0.3.2 for GitHub Actions.
July 11, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.31.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 744153cfade21c2ddbd0075fd9ae832ad6a8fb32 feat(cli): add anchors — surviving exemplar code per module (Build2 ①) (#359) 8063822db503221bd5ab410f7111800cb306422b feat(cli): add get-write-context — structured write context (MCP core) (#358) 2f549cf7ea29012ce21ff8af74e7368871d15974 feat(cli): add graveyard — where past attempts died (Build2 ②) (#361) f606b97d2751cda0237baebd82faf235294a6ba5 feat(cli): add precheck-hook — Claude Code PreToolUse debt injector (#357) 5072795f679b0af30de226f1f37e00a0d895c5ef feat(cli): add write-index — per-module index for AI coding agents (#356) 25c73e72fbb4366732a4254cff61545411be3c6c feat(cli): structural-debt Tier-1 meter (SDR, AI-agnostic) (#354) 4da4a8507f2b046b5b1236da5fe95d33512a6d9a feat(graveyard): drop non-code files (docs/config/images) from the death walk (#363) 19c93511030a250140bde0d9662fd0b2d0ef2c5f feat(mcp): add eis mcp — MCP stdio server exposing get_write_context (#364) 2fd32d6e069c9cfa283b8f3f2d7553d09e6dd21c feat(structural-debt): lean pipeline path (skip science debt never reads) (#355) 08032192b0c8fb08cc9ab5fd1b1536ae40a8a9f8 feat(timeline): expose per-period module survival-by-author; pin analysis instant (#366) c9b680d3ef1960d4f4c7f62f0988ed9c4fb4864d feat(write-index): wire anchors + graveyard into the per-module index (#365) fa697e1074f7558cc4640d6ffd918ebb1ff500bd fix(anchors): calibrate exemplar quality (core source + real-logic digests) (#360) 090079032c0b51fcb5bc009c924807cddf7a73b7 test(metric): adversarial fixtures for the contest detector (verify, don’t assume) (#362)
July 11, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.19.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.19 (2026-07-11)
July 11, 2026
Changelog Bot Runner Nyaomaru
Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(changelog): 0.6.4 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/157 fix: document exit codes and typed config errors by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/158 refactor: clarify category tuning rules by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/159 refactor: clarify release section rendering by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/160 Release: 0.6.5 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/161 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.5
July 11, 2026
Setup OCX
Version updated for https://github.com/ocx-sh/setup-ocx to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.3.0 — 2026-07-11 Added Support tar.gz archives with tar.xz fallback by @michael-herwig (ae06166) Release V1.3.0 by @michael-herwig (dbb4743)
July 11, 2026
spec.md check
Version updated for https://github.com/rosenjcb/spec.md to version v0.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed @rosenjcb/spec-md v0.3.4 Patch Changes Fix Claude Code plugin command names: files are action-only (update.md, check.md, coverage.md, new.md) so invocations are /spec-md:update, /spec-md:check, /spec-md:coverage, /spec-md:new. Previous spec:update.md / spec-update.md stems double-prefixed under plugin spec-md. Docs and a regression test lock the mapping. Install npm install --save-dev @rosenjcb/spec-md@0.3.4 npx @rosenjcb/spec-md check - uses: rosenjcb/spec.md@v0.3.4 GitHub Action Marketplace: automated releases do not check “Publish to Marketplace”. On the first release, open the release in GitHub and enable marketplace publishing manually. See RELEASING.md.
July 11, 2026
Auto-download resume from overleaf
Version updated for https://github.com/Sbrjt/overleaf-resume-syncer to version v2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Added google drive upload integration by @sahitya1903 in https://github.com/Sbrjt/overleaf-resume-syncer/pull/2 Full Changelog: https://github.com/Sbrjt/overleaf-resume-syncer/compare/v1...v2
July 11, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.3.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.3.0 Released 2026-07-11.
An operator-capability release. The dashboard gains authentication with scoped tokens whose every decision lands a governance receipt, a new agy adapter joins the matrix with a nightly conformance canary sealing its probe results, and the run review board projects the run journal into a web view backed by sealed evidence bundles. Groundwork lands for Windows parity and for installing bernstein as an agent skill or plugin.
July 11, 2026
The Slack GitHub Action
Version updated for https://github.com/slackapi/slack-github-action to version v3.0.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,705 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch Changes 96fddbe: fix: revert multiline yaml parsing indentation change
July 11, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.7.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.7 (2026-07-11) Features runtime: add collapsible review stats (#53) (5bb8fa3) This PR was generated with Release Please. See documentation.
July 11, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.
July 11, 2026
xilo-nix-cache
Version updated for https://github.com/stubbedev/xilo to version v0.2.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/stubbedev/xilo/compare/v0...v0.2.5
July 11, 2026
Pi Review Agent
Version updated for https://github.com/sun-praise/pi-review-agent to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Repository style-guide support: pi-review-agent can now load a repo-level style-guide and inject it into reviewer prompts. Auto-detected paths: STYLE_GUIDE.md, .github/STYLE_GUIDE.md, docs/style-guide.md, .github/style-guide.md. New built-in style persona dedicated to style-guide enforcement. quality persona now receives the style-guide by default. Custom personas can opt in via use-style-guide: true in .github/reviewers/*.yaml. Explicit override via --style-guide CLI flag or style-guide action input. Usage - uses: sun-praise/pi-review-agent@v1 with: team: "quality:1,style:1,security:1" style-guide: "./docs/STYLE_GUIDE.md" litellm-url: ${{ secrets.LITELLM_URL }} litellm-api-key: ${{ secrets.LITELLM_API_KEY }} Refer to README.md for full documentation.
July 11, 2026
Ansible Molecule
Version updated for https://github.com/gofrolist/molecule-action to version v2.9.2.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.9.2 (2026-07-11) This release is published under the MIT License.
Bug Fixes deps: Bump astral-sh/uv from 0.11.27 to 0.11.28 (83bf83d) Detailed Changes: v2.9.1…v2.9.2
July 11, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.431.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/533303a1e5604620ca7e806d750472a99379d081 with plugin-scanner 2.0.1031.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.430...v1.2.431
July 11, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.431.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.431
July 11, 2026
action-lambda-publish
Version updated for https://github.com/heronlabs/action-lambda-publish to version v4.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.2 (b2b33b4) chore(deps): bump heronlabs/action-tag-release-build (#25) (9bc047e) [skip ci] bump v4.0.1 (a3343a0) chore: migrate supera.json to 2.x + doc fix (#26) (22a5ee0) [skip ci] bump v4.0.0 (401b931) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446) [skip ci] bump v3.0.14 (2a7a37c) chore: add CODEOWNERS file to define repository ownership (82d7d6e) [skip ci] bump v3.0.13 (02e3934) Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6)
July 11, 2026
hide-comment
Version updated for https://github.com/int128/hide-comment-action to version v1.65.0.
This action is used across all versions by 228 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: int128/hide-comment-action@7938621b1746abfe9727d44c8f6c47d5485192ca # v1.65.0 What’s Changed Remove unused js-yaml dependency by @int128-actions-tanpopo[bot] in https://github.com/int128/hide-comment-action/pull/1650 chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1652 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.64.0...v1.65.0
July 11, 2026
stackit-cli tools installer
Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.87.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-stackit-cli/pull/284 Full Changelog: https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.86...v1.2.87
July 11, 2026
probelock gate
Version updated for https://github.com/kelkalot/probelock to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Refine release workflow to match only version tags by @kelkalot in https://github.com/kelkalot/probelock/pull/7 Release 1.0.0: stability, doctor, robustness by @kelkalot in https://github.com/kelkalot/probelock/pull/8 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v1.0.0
July 11, 2026
aria-reach — ARIA anti-pattern scan
Version updated for https://github.com/manichandra/aria-reach to version v0.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed projection-aware listbox rule; cross-ecosystem scan harness
July 11, 2026
Setup Marmot
Version updated for https://github.com/marmotdata/setup-marmot to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/marmotdata/setup-marmot/commits/v0.1.0
July 11, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.92.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 11, 2026
Agent Behavior Safety Gate
Version updated for https://github.com/NavidBroumandfar/agent-behavior-evals-lab to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Real-agent fleet calibration (320 records, 3-judge panel), verifier red-team hardening, refusal-under-temptation corpus (local_public_v3), measured eval-awareness reports, laundered-refusal demo record shipped in the offline gate demo. Full details in README and reports/comparisons/.
July 11, 2026
Nox Security Scanner
Version updated for https://github.com/Nox-HQ/nox to version v1.8.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.8.0 (2026-07-10T20:09:28Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Features 447c45f37e18f308f1ca17822f8ebdd195da2746 feat(server): return structured content from read/report tools (#230) Others 8d3112f55e43db84eecca7e93e7e92b10ac1aa30 chore(deps): bump go.klarlabs.de/mcp to v1.21.0 (#227) 9baa04fcda33d5fd30e84cf8600998565dd598a4 chore(deps): bump go.klarlabs.de/mcp to v1.22.0 (#229) d75e6e26ce0a297c164491dd4a27bfc757b6e1e4 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-grc (#228) Full Changelog: https://github.com/nox-hq/nox/compare/v1.7.1...v1.8.0
July 11, 2026
start-aws-gha-runner
Version updated for https://github.com/omsf/start-aws-gha-runner to version v1.3.0.
This action is used across all versions by 10 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: support spot runners by @jandom in https://github.com/omsf/start-aws-gha-runner/pull/7 New Contributors @jandom made their first contribution in https://github.com/omsf/start-aws-gha-runner/pull/7 Full Changelog: https://github.com/omsf/start-aws-gha-runner/compare/v1.2.0...v1.3.0
July 11, 2026
Rosentic - Cross-Branch Compatibility Check
Version updated for https://github.com/Rosentic/rosentic-action to version v1.8.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Catches when AI-agent branches break each other’s contracts before merge. 13 languages, AST-level, runs on your CI runners. The engine goes to the code; the code never goes to the engine unless you send it.
July 11, 2026
MCPShield MCP Config Scan
Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes discover_files no longer crashes when an absolute path or glob is passed to --paths (pathlib rejects non-relative glob patterns). Standard CI usage passes repo-relative paths and was unaffected.
July 11, 2026
Sentinel Git Secrets Scanner
Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/sentinel-cli/sentinel/compare/v2.0.5...v2.0.6
July 11, 2026
The Slack GitHub Action
Version updated for https://github.com/slackapi/slack-github-action to version v3.0.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,704 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch Changes fa03fe4: refactor: send webhooks with the @slack/webhook package
July 11, 2026
Skill Provenance Validate
Version updated for https://github.com/snapsynapse/skill-provenance to version v5.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 5.0.0 - 2026-07-10 Security hardening release for Skill Provenance manifest validation and its GitHub Actions wrapper.
Security fixes Prevented bundle-path shell injection by transporting caller-controlled action input through an environment variable instead of interpolating it into Bash source. Made verify mode fail closed on missing, malformed, or duplicate manifest hash fields. Added explicit hash: null as the only intentional hash-verification opt-out. Made update mode repair missing or malformed hashes while preserving explicit null opt-outs. Kept inventory presence checks active for files whose hashes are explicitly opted out. Tests and evals Added executable CI regressions for action input transport and validator hash states. Added adversarial quote, separator, command-substitution, newline, and spaced-path action coverage. Added core evals for fail-closed verification, explicit null semantics, and update repair. Added a supplemental eval for GitHub Action shell safety. Expanded coverage from 46 to 50 scenarios: 33 core and 17 supplemental. Breaking change Manifest entries may no longer omit the hash field. Use a complete lowercase sha256: value or explicit hash: null. This intentional contract tightening requires the 5.0.0 major version.
July 11, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.
July 11, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.57.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update cachix/install-nix-action action to v31.10.7 (#159) (97318f9a6c3ec7b40483d6b25bf8d308a213eb20) bump: v1.56.0 -> v1.57.0 (a381c8e0765c98cb84fdc4a392eefd6c4db309a5) chore(deps): update github actions to v1.56.0 (#158) (88f6dbaed49ea12307fa5ea2c1b5a81dfa70a932)
July 11, 2026
Azure Static Web Apps Deploy (small)
Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Azure Static Web Apps Deploy (small) Features:
Deploy to Azure Static Web App 📦without a massive docker container 🐋 Support for federated credentials 🔑 and the less secure API token What’s Changed Remove extra colon by @arlobelshee in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Adjust README and update workflow to use azure/login@v3 by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3 Fix: failed SWA CLI deployment not propagating as action failure by @svrooij with @Copilot in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/5 New Contributors @arlobelshee made their first contribution in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.2.0
July 11, 2026
agentslint
Version updated for https://github.com/toshi0607/agentslint to version v0.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of agentslint — a CI linter for AI coding agent config files (AGENTS.md, CLAUDE.md, .claude/).
Highlights 6 rules: broken file references (AL001), stale commands (AL002), token budget (AL003), skill frontmatter (AL004), settings schema with 125 known keys (AL005), secret patterns (AL006) 4 output formats: pretty, JSON, SARIF (GitHub code scanning), GitHub annotations GitHub Action with PR inline annotations, job summary, and optional SARIF output --help / --version, zero-config npx @toshi0607/agentslint Tested on Ubuntu / macOS / Windows (47 tests) Usage - uses: actions/checkout@v4 - uses: toshi0607/agentslint@v0.0.2 See the README for CLI usage, configuration, and the code scanning setup.
July 11, 2026
Magic Review OPENAI Code Review Action
Version updated for https://github.com/yuri-val/ai-codereviewer to version v4.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new since v3 Default model is now gpt-5.6-luna (was gpt-4o). Any model can still be set via the OPENAI_API_MODEL input. Prompts overhauled for the GPT-5.6 family: strict JSON output contract (response_format: json_object), severity levels (critical/major), line-number-anchored comments with GitHub suggestion blocks. Hardened review pipeline: concurrent per-file reviews, full-file context fetching, retry with exponential backoff on rate limits/5xx, adaptive completion-token budgets for reasoning models, comment batching with 422/403 fallback. OpenAI SDK upgraded to 4.104, Octokit to 21.x, action runtime on node20. Usage - uses: yuri-val/ai-codereviewer@v4 with: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} OPENAI_API_MODEL: "gpt-5.6-luna" exclude: "**/*.lock,dist/**,**/*.json,**/*.md"
July 11, 2026
Auto PR dev to main/master
Version updated for https://github.com/yuri-val/auto-pr-action to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes in this Release:
feat: default to gpt-5.6-luna and tune prompt for GPT-5.6
Switch the default model from gpt-5.4-mini to gpt-5.6-luna
Rewrite the system prompt per the GPT-5.6 prompting guide: lean instructions, real newlines (previously literal \n sequences), clear output contract (summary + emoji sections, no title/preamble)
July 11, 2026
Auto-generate PR Description
Version updated for https://github.com/yuri-val/auto-pr-description-action to version v1.6.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes in this Release:
feat: default to gpt-5.6-luna, tune prompt and token budget
Switch the default model from gpt-5.4-mini to gpt-5.6-luna
Rewrite the prompt per the GPT-5.6 prompting guide: lean system prompt with a clear output contract, diff moved to the user message
July 10, 2026
Agentic Workflow Guard
Version updated for https://github.com/jinyounghub/agentic-workflow-guard to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.2.0 Public OSS release focused on real-world adoption: noise control, data-flow precision, catalog verification, and contributor onboarding.
Added Config file support with rule disable, severity override, path excludes, and narrow suppressions. Baseline support for accepted existing findings. Finding fingerprints and active/suppressed/baselined report state. Improved GitHub expression handling and one-step env data-flow detection for AI output references. Verified AI action catalog metadata and documentation. Contributor onboarding docs and beginner-friendly synthetic fixtures. Verification npm run lint npm test npm run build npm audit –audit-level=moderate npm pack –dry-run workflow self-scan fixture scans SARIF JSON parse check
July 10, 2026
sops tools installer
Version updated for https://github.com/jkroepke/setup-sops to version v1.5.51.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/246 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.50...v1.5.51
July 10, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.86.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.2 (2026-07-10) Bug Fixes (anthropic): prompt-cache breakpoints + accounting parity for the direct-Anthropic path (66df1ae)
July 10, 2026
Krystal Quorum Multi-AI Plan Review
Version updated for https://github.com/KrystalUnity/krystal-quorum to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Krystal Quorum v0.7.0 adds an agent-native two-gate workflow: review the implementation plan before coding, then verify the resulting diff against the approved commitments.
What’s new Automatic two-gate policy packs for Claude Code, Codex, GitHub Copilot, Hermes, OpenClaw/Claw, and OpenCode. Bound plan approvals and verified implementation-diff review. Deterministic commitment extraction, evidence reconciliation, and persisted review receipts. A standalone krystal-quorum diff gate for local workflows and CI. Expanded CI coverage across Ubuntu and Windows on Python 3.11/3.12, plus macOS on Python 3.12. Internal SDD workspace artifacts are excluded from the public package and repository. Install pip install --upgrade krystal-quorum krystal-quorum demo PyPI: https://pypi.org/project/krystal-quorum/0.7.0/
July 10, 2026
Apex Backtest Check
Version updated for https://github.com/mickeyappol-create/apex-backtest-check to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First report-only release. Uses GitHub Actions OIDC with audience https://api.smartapex.uk, calls bounded DATA ONLY diagnostics, and writes receipt-backed results without exposing returns in logs or summaries.
July 10, 2026
helm-scribe
Version updated for https://github.com/Miosp/helm-scribe to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add Kubernetes type annotations by @Miosp in https://github.com/Miosp/helm-scribe/pull/5 Add Github Action by @Miosp in https://github.com/Miosp/helm-scribe/pull/6 Add a partial and strict schema option for k8s types by @Miosp in https://github.com/Miosp/helm-scribe/pull/7 Structural refactor and bug fixes by @Miosp in https://github.com/Miosp/helm-scribe/pull/8 Full Changelog: https://github.com/Miosp/helm-scribe/compare/v0.1.0...v0.2.0
July 10, 2026
Agent Security Harness
Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Corrects a CVE misattribution. The MCP tool-poisoning suite was incorrectly anchored to CVE-2026-25253, which is an unrelated OpenClaw WebSocket vulnerability. Re-anchored to the Invariant Labs Tool Poisoning research (2025) and ClawHub RFC #99; fabricated statistics removed; module renamed cve_2026_25253_harness to mcp_tool_poisoning_harness (CLI id mcp-tool-poisoning). Test IDs CVE-001..CVE-010 unchanged; CVE-009/010 still map to the real CVE-2026-35625/35629. 540 tests.
July 10, 2026
AI Agent Discipline Linter
Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.21.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(hooks): keep lifecycle hooks working without Bash by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/284 feat(simplicity-review): diff-scoped over-engineering review skill (Law 4) by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/285 feat(production-readiness-review): add simplicity dimension delegating to simplicity-review by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/286 chore(release): cut v3.21.0 by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/287 Full Changelog: https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.21.0
July 10, 2026
Firefly Numerical Parity Check
Version updated for https://github.com/neelvad/firefly to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/neelvad/firefly/compare/v0...v0.6.0
July 10, 2026
rust-audit-check-action
Version updated for https://github.com/pirafrank/audit-check-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release with stable functionality.
July 10, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.33.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed UI 🔄 Changed RBAC role forms now explain Unlimited Visibility inside the Visibility section and keep the setting visible while group selection is hidden (#11890) 🐞 Fixed CIS Level 1 and Level 2 compliance filters now match profiles prefixed with a license tier (e.g. “E3 Level 1”), so M365 CIS requirements are no longer hidden (#11924) Jira dispatch polling now reports failed issue creation tasks instead of treating partial failures as successful (#11925) API 🐞 Fixed Session tokens are rejected after account password updates (#11914) Jira dispatch task results now surface user-facing Jira failure messages (#11925) AWS Attack Paths privilege escalation queries no longer fail on Neo4j with Aggregation column contains implicit grouping expressions (#11939) 🔐 Security OpenAI-compatible Lighthouse provider base URLs are restricted before connection checks (#11940) LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS environment variable to allow internal hosts as OpenAI-compatible Lighthouse AI base URLs (#11942) SDK 🐞 Fixed ECS task definition resource limits now select the latest task definitions by registration date instead of relying on ARN ordering (#11891) dlm_ebs_snapshot_lifecycle_policy_exists no longer initializes the full EC2 inventory just to detect EBS snapshots, avoiding slow scans when checking DLM lifecycle policies (#11900) dms_instance_no_public_access no longer initializes the full EC2 service when there are no DMS replication instances (#11902) organizations_scp_check_deny_regions no longer reports false FAIL for AWS Organizations that restrict regions with Allow-based SCPs; the Allow path now checks the statement Effect instead of an always-false comparison that made it unreachable (#11915) Jira issue creation failures now preserve safe structured response details from Jira (#11925) Azure Function App optional permission failures now log as warnings, and Function App environment variable fields use the correct spelling internally (#11926)
July 10, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.15.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Closes REMYX-195 with a mode-aware pre-PR fidelity gate and lands the lead-content input for spec-driven dispatches beyond arXiv paper implementations.
Mode-aware fidelity gate The pre-PR fidelity gate now routes by the coding session’s cited implementation mode instead of applying one strict method-vs-diff comparison to every output:
July 10, 2026
Hey Sysmon
Version updated for https://github.com/rezen/action-hey-sysmon to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Edit action description (42e29a5) Fix ci job for blocked 1.1.1.1 (5c4734d) Update CI job for generating test telemetry (a8b71f0) Add windows firewall options (801ed7c) Add IP lookups when api keys are provided (fb2211c) Fix ci tests (c8e538f) Add parsing of sysmon logs (91b4673) Bump nodejs version (1e0c563) Work on error GITHUB_ACTION_PATH is not set (17e6609) Fix CI: add lockfile, commit dist bundle, move to Node 24 (5eb8ada)
July 10, 2026
codemetrics complexity gate
Version updated for https://github.com/richardwooding/codemetrics to version v0.12.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Features c64006d90f94e7b0fbc6f2141e236249f7fa1d5a: feat: add OpenGraph/Twitter preview image and meta tags (@richardwooding) 3218fa7d1ee90ebd0eefa0e9957b04b6a2aa4b8a: feat: install Google Tag Manager (@richardwooding) Others 313ec8bf15620f34e7b22aad4928ea8d48141fdc: chore(site): sync gloam assets to c2daafe2a5a046e61f2cce23a514fb9114b20e0e (#23) (@github-actions[bot]) a5b6a6302e89eaa3a61b543bae40cf8275eda960: docs(readme): use labeled Markdown link for website (#21) (@richardwooding) b9743bec9e6c7c739608dfba53955d00666a6e30: refactor(site): adopt the gloam design system (#19) (@richardwooding)
July 10, 2026
file-search-on review gate
Version updated for https://github.com/richardwooding/file-search-on to version v0.119.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Others f163b11e6aa561a3e52c1c48151098ca17c50358 chore(deps): Bump the minor-and-patch group across 1 directory with 6 updates (#559)
July 10, 2026
MCPShield MCP Config Scan
Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Hardcoded-secret detection: flags embedded credentials in MCP config commands (AWS / GitHub / Slack / OpenAI / Anthropic / Google keys, private-key blocks, inline DB connection-string passwords), scored +30 as a typed finding. Only the credential type is surfaced, never the value. Parity with the MCPShield 0.4 engine. - uses: RunTimeAdmin/mcpshield-action@v1 with: fail-on: high
July 10, 2026
SCP File or Directory Transfer to Remote
Version updated for https://github.com/shoops/scp-action to version v-1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merged action version updates from upstream
July 10, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.2.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.2.0 Released 2026-07-10.
A resumability and availability release. Interrupted runs continue from a verified ledger instead of starting over, provider outages reroute along declared fallback chains with a receipt for every decision, and certified local endpoints join the worker pool behind a certification gate.
July 10, 2026
Normalize Major Version Tag
Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.0.4
1.0.4 (2026-07-10) 📚 Documentation README: update overview (322b533)
July 10, 2026
Azure Static Web Apps Deploy (small)
Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Azure Static Web Apps Deploy (small) Features:
Deploy to Azure Static Web App 📦without a massive docker container 🐋 Support for federated credentials 🔑 and the less secure API token What’s Changed Remove extra colon by @arlobelshee in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Adjust README and update workflow to use azure/login@v3 by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3 New Contributors @arlobelshee made their first contribution in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.1.0
July 10, 2026
ArchGuard - Architectural Drift Detector
Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 80cfe34913c47307c4b563275df0d306edf7e74b perf: optimize vector indexing and provider concurrency (#23)
July 10, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.710.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.710.1 Released 2026-07-10
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.709.2, interleaved on one runner against the pinned corpus (157 metrics compared).
July 10, 2026
SignalBrain receipt gate
Version updated for https://github.com/whitestone1121-web/signalbrain to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ## SignalBrain 0.1.5
Patch release aligning the public package with the current public repo and outreach story.
Highlights Adds the public field audit: 560 agent PRs, 8 agents, reproducible harness, and ledger. Generalizes sb report so calibration curves can be generated from any ledger. Fixes measure parsing around shell command substitutions/env-prefix detection. Improves Windows test portability and public package CI coverage. Adds the free compute harness and autonomous agent review beacon. Validation Public CI passed on Linux, macOS, Windows, Python 3.11-3.14. PyPI trusted publishing completed successfully. Fresh install smoke passed for signalbrain==0.1.5.
July 10, 2026
Move Closed Issue to Top of Project Column
Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.20.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: wozaki/project-closed-issue-move-to-top-action@38201418e7fb26572a663b92b727c7467690fb8a # v1.20.0 What’s Changed chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/149 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/150 chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/151 Full Changelog: https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.19.0...v1.20.0
July 10, 2026
Setup Backlog CLI
Version updated for https://github.com/yacchi/backlog-cli to version v0.30.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog e7435b677ee9c2feb440dcbcfeeb048901250309 docs(mcp): SERVER_INSTRUCTIONS にパッチ編集の使い方を追加 45715d0887ba1e06b1e035b5cbe950431dd92ba3 fix(cache): mutation後のキャッシュ無効化とMCPサーバーでのキャッシュ無効化
July 10, 2026
vibecheck-ai-slop
Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed CI ergonomics and CLI polish. Everything here makes vibecheck easier to wire into pipelines that are not GitHub Actions, and nicer to read when they are.
New flags
--fail-on <error|warn|info|never>: pick the severity that fails the run (default error, same as before) --max-warnings <n>: fail when warnings exceed a budget --format <pretty|compact|json|quiet|gh>: compact prints one clickable path:line:col line per finding; gh emits GitHub Actions annotations so you get PR annotations from a plain run: step, no marketplace action needed --diff-stdin: scan any piped unified diff, e.g. gh pr diff 42 | vibecheck --diff-stdin . --statistics: per-rule finding counts (ruff-style), also in JSON output vibecheck rules: list all 39 rules with severity, category, languages, and fixability (--json for machines) Output
July 10, 2026
MUADDIB Scanner
Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.164.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan-ledger compaction (500K entries, 127MB) converted from synchronous to async streaming. Main-thread lag drops from minutes to <30ms. Sync finalization prevents append loss. Breaker stays reactive during compaction.
July 10, 2026
GitHub Metadata action
Version updated for https://github.com/dockerbakery/github-metadata-action to version v5.2.
This action is used across all versions by 45 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dockerbakery/github-metadata-action/compare/v5.1...v5.2
July 10, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.34.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.
July 10, 2026
RunRight CI Resource Monitor
Version updated for https://github.com/gbudjeakp/run-right to version v1.6.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed runright v1.6.1 Download the binary for your platform below, or use the GitHub Action:
- uses: gbudjeakp/run-right@v1.6.1 with: step: start Changelog
July 10, 2026
Plumber Score
Version updated for https://github.com/getplumber/plumber to version v0.4.0.
This action is used across all versions by 22 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.4.0 (2026-07-10) One grade, one gate: the Plumber Score Until now, Plumber gave you two competing verdicts: 1. The Plumber Score (A–E, severity-weighted) 2. A compliance percentage (share of passing controls, severity-blind)
They could disagree: one Critical finding in a single control read as “95% compliant” while scoring an E. And only the percentage gated your CI.
July 10, 2026
Validate ProductSpec files
Version updated for https://github.com/gokulrajaram/ProductSpec to version v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ProductSpec v0.10.0 This release keeps the Product Spec document shape at spec_format_version: "0.1" and updates the reference parser, schema, docs, and conformance suite.
Added Fenced-code-aware section parsing. ## headings inside Markdown code samples no longer create duplicate or out-of-order ProductSpec sections. target_status: committed | provisional for structured Success Metrics. target_owner for provisional Success Metric targets, so teams can record honest post-launch target calibration without turning guesses into committed intent. Published package @productspec/parser@0.10.0 Validation Parser test suite passes. ProductSpec and Decision Trace conformance fixtures pass. npm publish dry-run passed before publishing the parser package.
July 10, 2026
proof-gate
Version updated for https://github.com/gregbond/proof-gate to version v0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of proof-gate.
proof-gate makes done require a proof class and inspectable evidence. It distinguishes local, CI, deploy, runtime, DB, visual, and no-go claims, then reports the honesty depth of each verifier.
Install:
July 10, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.417.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/c5888f576d976f2cc27b8133cbdbe6ae3debb271 with plugin-scanner 2.0.1017.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.416...v1.2.417
July 10, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.417.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.417
July 10, 2026
Hyperlocalise CI
Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.23.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(web): add file tree search and context menu actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1343 test(web): cover project file action gating by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1344 fix(crowdin): optimize JoinSlice for task-related enums by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1347 fix(web): prevent file action and sandbox translation regressions by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1346 fix(web): show TMS project name in glossary and TM pickers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1348 fix(dashboard): remove nested cards from overview panels by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1349 fix(web): theme tree search and portal row file actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1350 fix(agent): route recent translations to repo git history by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1351 refactor(ci): simplify web localization sync to direct hl commands by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1352 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1354 feat(web): wire content locales ahead of routing support by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1355 feat(web): enable app locales and add language toggle by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1356 fix(web): polish locale toggle labels and reload on change by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1357 feat(web): localize dashboard overview with react-intl by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1358 feat(cli): add –max-translations session limit for paginated runs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1359 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.23
July 10, 2026
Codex Action
Version updated for https://github.com/icoretech/codex-action to version v0.9.18.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.18 (2026-07-10) Bug Fixes deps: update codex-docker image to v0.144.1 (#50) (c4dc375)
July 10, 2026
aeroflare-test-action
Version updated for https://github.com/ItzEmoji/aeroflare-test to version v1.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.9.1 (2026-07-10) Bug Fixes upstream-cache filtering in github-action (330fda0)
July 10, 2026
stackit-cli tools installer
Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.86.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-stackit-cli/pull/283 Full Changelog: https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.85...v1.2.86
July 10, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/kewang/spek to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hideable tree navigator (IntelliJ) — the Specs / Changes tree in the spek tool window can now be hidden from the tool window title bar or its gear (⋮) menu, giving the viewer the full tool window. The choice is remembered per project, and the split ratio is persisted too instead of resetting every time you reopen the project. While hidden, the tree no longer rebuilds on file changes; it refreshes when you bring it back. Thanks to @deniskrizanovic for reporting.
July 10, 2026
Local Mac iOS Build Action
Version updated for https://github.com/local-mac-ci-cluster/local-mac-runner-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Local Mac CI Cluster GitHub Marketplace 一键接入自有本地Mac CI集群工具
功能说明 本Action用于组织内部所有业务仓库快速接入自建10台Apple Silicon Mac算力池,无需修改原有 workflow 的 runs-on: macos-latest 配置,一行代码即可零成本切换本地自建Mac构建,不再消耗GitHub官方付费云Mac资源。
快速接入教程 1. workflow顶部引入本Action 无需配置任何密钥、凭证,仅增加一行uses语句即可生效。
完整业务workflow参考示例 ```yaml name: iOS项目构建测试 on: [push]
jobs: build_task: runs-on: macos-latest steps: - uses: local-mac-ci-cluster/local-mac-runner-action@v1 - uses: actions/checkout@v4 - name: 本地环境校验 run: sw_vers && xcodebuild -version ```
July 10, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: compress context further by tidying up messages by @louisescher in https://github.com/louisescher/crabd/pull/25 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/26 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.5.1
July 10, 2026
AI Code Review by n-devs
Version updated for https://github.com/n-devs/ai-code-review to version v2.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: update default model to openai/gpt-5-mini and correct GitHub Mod… by @n-devs in https://github.com/n-devs/ai-code-review/pull/3 Full Changelog: https://github.com/n-devs/ai-code-review/compare/v1.0.0...v2.0.0
July 10, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.33.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release fixing two false positives in the litmus-v16 scanners, both found by a local regrade of the published set (#115).
raven-mcp (was A→F): C-01 tool-poisoning. The exfil-instruction check tested the sink against the whole document, so a benign UI-docs surface that listed form fields ('Email', 'Password') and carried a URL elsewhere tripped it. The sink is now required in the same clause as the verb and object (one bounded, linear regex).
July 10, 2026
docker-hash
Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Bug fixes fix(deps): update dependency markdownlint-cli2 to v0.23.0 (#167)
July 10, 2026
Setup JavaScript/TypeScript Environment
Version updated for https://github.com/siguici/setup-js to version v1.3.1.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/siguici/setup-js/compare/v1.3.0...v1.3.1
July 10, 2026
Agent Gate for AI PRs
Version updated for https://github.com/sjh9714/Agent-Gate to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agent Gate v0.3.1 Release Notes Agent Gate v0.3.1 is the first public CLI release of the v0.3 line. The npm package is scoped as @jinhyuk9714/agent-gate; the executable and product name remain agent-gate and Agent Gate.
July 10, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.6.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.6 (2026-07-10) Features harden review prompts and recipes (#51) (59cf563) Bug Fixes gate suggested fixes in prompt evals (#49) (86daeca)
July 10, 2026
Deploy to Vercel
Version updated for https://github.com/Spectra010s/d-vercel to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Added ignore-build-step input option to skip the build step when needed. Improvements Gives users more control over the deployment workflow. Useful for projects where the build is handled separately before deployment. Usage Set ignore-build-step in your workflow with a command to skip the build step.
July 10, 2026
MCP Test Harness
Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 3.0.4 Fix GitHub Action actions/github-script@v8.0.0 commit pin (dist-smoke + Marketplace). All 18 PyPI packages and GHCR images at 3.0.4. See CHANGELOG.md.
July 10, 2026
cloudflare-script
Version updated for https://github.com/wei/cloudflare-script to version v7.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Update Cloudflare SDK from v6.5.0 to v7.0.0 This release was generated automatically when a new Cloudflare SDK version became available.
July 10, 2026
vibecheck-ai-slop
Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Trust fixes. Every change here came out of an adversarial review pass over the rule regexes and scanner.
False positives killed (these were failing CI on normal code):
no-py-eval no longer flags model.eval() / df.eval() (every PyTorch and pandas repo) no-eval no longer flags Playwright/Puppeteer page.$eval(), still catches window.eval() no-sql-concat / no-py-sql-concat now require a real SQL clause, so “Update available: " + version and friends stop flagging no-innerhtml no longer flags === comparisons False negatives fixed:
July 10, 2026
Wardex Release Gate
Version updated for https://github.com/had-nu/wardex to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog d55fd9bffbe196698aa6f2f1e8bc3dc828ee3372 chore(v2.3.0): make gleipnir dep public, remove replace directive bee2ba9d2d0df89d52405f399244fb8f27e9c453 feat(v2.3.0): replace immutable-provenance sub-module with agnostic Anchorer interface a5a3bfc18b2a69ec1fe8e691728084cfc4094d8a docs: add signing public key and root hash to READMEs for v2.2.2 verification be4ebfab9dc6ce8233f018eccc9e425d02250b73 docs: update English README with same structure as Portuguese 3cca9599cf0283debfb0eabb72733bb88cf0dd50 docs: restructure README — audit log como feature principal, posicionamento europeu 52fd3345022aad1b2faf4378fd8135497ef982cd refactor: migrate key storage to ~/.crypto/ centralized directory
July 10, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.416.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/8ed11fda90343fdef4651bfc5dcd4db0110910fa with plugin-scanner 2.0.1016.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.415...v1.2.416
July 10, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.416.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.416
July 10, 2026
HCL AppScan Static Analyzer
Version updated for https://github.com/HCL-TECH-SOFTWARE/appscan-sast-action to version v1.1.0.
This action is used across all versions by 133 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Incremental scanning option when run on pull requests. Rescan option for SAST and SCA
July 10, 2026
action-env-sync-build
Version updated for https://github.com/heronlabs/action-env-sync-build to version v4.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.1 (6138dc1) chore: update bats-action version to 4.0.0 in CI workflow (2835391) [skip ci] bump v4.0.0 (35c0b3c) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (2d87bff) [skip ci] bump v3.0.16 (928b5e4) chore: add CODEOWNERS file to define repository ownership (0b2a78c) [skip ci] bump v3.0.15 (289366a) Merge pull request #17 from heronlabs/chore-dependabot-daily (ff6c7d1) chore: set dependabot interval to daily (5d7a13f) [skip ci] bump v3.0.14 (6c3b726)
July 10, 2026
action-lambda-publish
Version updated for https://github.com/heronlabs/action-lambda-publish to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.0 (401b931) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446) [skip ci] bump v3.0.14 (2a7a37c) chore: add CODEOWNERS file to define repository ownership (82d7d6e) [skip ci] bump v3.0.13 (02e3934) Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6) chore: set dependabot interval to daily (943baaf) [skip ci] bump v3.0.12 (0657d06) chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda) [skip ci] bump v3.0.11 (d90741b)
July 10, 2026
action-pulumi-build
Version updated for https://github.com/heronlabs/action-pulumi-build to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v3.0.0 (4b38180) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (39c2181) [skip ci] bump v2.0.17 (dc269c7) chore: add CODEOWNERS file to define repository ownership (3a74494) [skip ci] bump v2.0.16 (f91a339) Merge pull request #23 from heronlabs/chore-dependabot-daily (daa055f) chore: set dependabot interval to daily (6eb3516) [skip ci] bump v2.0.15 (4a8ed93) chore: update action-pulumi-build to action-tag-release-build v5.0.12 (#22) (6381c2f) [skip ci] bump v2.0.14 (0c60e15)
July 10, 2026
action-ssm-env-build
Version updated for https://github.com/heronlabs/action-ssm-env-build to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.0 (629adc8) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (875ca5f) [skip ci] bump v3.0.17 (b183979) chore: add CODEOWNERS file to define repository ownership (2f161c4) [skip ci] bump v3.0.16 (69d8a26) Merge pull request #27 from heronlabs/chore-dependabot-daily (49378ce) chore: set dependabot interval to daily (1bc293e) [skip ci] bump v3.0.15 (7fab56e) chore: update action-ssm-env-build to action-tag-release-build v5.0.12 (#26) (2109b62) [skip ci] bump v3.0.14 (97ddc90)
July 10, 2026
action-tag-release-build
Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v6.0.0 (0994531) [skip ci] bump v5.3.1 (9d405f0) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (19337c6) [skip ci] bump v5.3.0 (b6256bf) feat: add CODEOWNERS file and update continuous deployment workflow (25d0edf) [skip ci] bump v5.2.1 (1a1d2c3) chore: ignore gts-locked packages in dependabot (#30) (dd25bcb) [skip ci] chore: update bin/ build artifact (ea43f9a) [skip ci] bump v5.2.0 (d3e5b7d) feat: create composite action + workflow to build and commit bin/ artifact (#27) (3c68e26)
July 10, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.5
July 10, 2026
aeroflare-test-action
Version updated for https://github.com/ItzEmoji/aeroflare-test to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.9.0 (2026-07-09) Features add make build/test/hash/get (639f89c) ci action (d4052a9) scripts: add get.sh to fetch a verified prebuilt binary (f81dcf0) Bug Fixes nix: build from the local tree instead of a self-referential fetch (c95b32d)
July 10, 2026
Cartulary Markdown Validator
Version updated for https://github.com/jdhorne/cartulary to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/jdhorne/cartulary/compare/v0.2.0...v0.3.0
July 10, 2026
sops tools installer
Version updated for https://github.com/jkroepke/setup-sops to version v1.5.50.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/245 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.49...v1.5.50
July 10, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.85.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.85.0 (2026-07-09) Features (skills): add native skills support (stores, tools, prompt index, CLI, API) (f7bd694)
July 10, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.1 A hardening hotfix for the v10.0.0 surface. An extreme end-user validation sweep — 275 clean-room scenarios run against a seven-lab test project — surfaced 37 confirmed defects. All 37 are fixed here, each pinned by a focused regression test.
July 10, 2026
SecondBrainAction
Version updated for https://github.com/mcasperson/SecondBrain to version +run3077-attempt1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
July 10, 2026
Miso PR Review
Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(github-action): update action actions/setup-python (a309ff8 → ece7cb0) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/402 ci(github-action): update action misospace/pr-reviewer-action (v2.0.5 → v2.1.1) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/403 perf(planner): share section piece files with the corpus so verdict dedup drops them by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/404 refactor(planner): extract embedded sections from the corpus itself; fix budget overflow dropping the diff head by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/405 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.1.1...v2.1.2
July 10, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.94.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(cloud): roll up account→resource OWNS in org hierarchy (#3742 PR 1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3743 feat(cloud): complete live EXPOSED_TO network paths (#3742 PR 2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3744 fix(api): dedupe CIS checks per scan and surface persist failures by @msaad00 in https://github.com/msaad00/agent-bom/pull/3746 fix(deploy): SPCS native-app install blockers + deploy hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3747 fix(ui): clean, actionable sign-in screen by @msaad00 in https://github.com/msaad00/agent-bom/pull/3748 feat(api): opt-in anonymous viewer alongside configured credentials by @msaad00 in https://github.com/msaad00/agent-bom/pull/3749 chore(deps): combine compatible July 9 dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3758 feat(cloud): network entry EXPOSED_TO paths (#3742 PR 4) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3759 feat(cloud): cross-account inventory → toxic + fusion (#3742 PR 5) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3760 fix: pre-release graph-accuracy + anonymous-viewer hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3761 docs(readme): fold intro, Quickstart next, Snowflake vendor lockup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3763 chore(release): 0.94.2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3762 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.94.1...v0.94.2
July 10, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Grading hardening: litmus-v16 (bundle schema 1.9.0).
Coverage cap with sandbox exercise. The dynamic probes skip actively calling state-changing (write) tools on the host path so the harness can’t move money or mutate real state. Under Docker isolation the target runs with no network in a throwaway sandbox, so those tools are exercised by default and a write-capable server earns A on the same terms as a read-only one. The cap fires only where a call would hit a live backend (host path or a remote https target): one high-risk tool left unexercised caps at B, and an unexercised destructive tool together with an unverified category compounds to C.
July 10, 2026
Shiro Automation
Version updated for https://github.com/rajitk13/shiro-automation to version v20260525-103919-ba52c2c.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: add version flag with ldflags injection at build time (ba52c2c) feat: add Docker image for CI/CD with GitHub Actions build workflow (325dc30) docs: add CI validation section to README (e97bbbf) feat: add CI cross-validator to shiro validate –ci flag (88b2a44) fix: migrate GitLab CI from building from source to using pre-built GitHub releases (119737c) docs: update README with GitHub releases, subprocess modules, Jira example, fix outdated CI examples (d1b6f70) fix: update install-auto.sh to use GitHub releases instead of GitLab CI (1377cb4) refactor: remove tech debt - unused version.go, ModuleReviews struct, and .bak file (82840ec) fix: use full github.com path with @latest for go run remote packages (a5ce9c6) fix: auto-release should trigger on both main and master branches (63d37a9)
July 10, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.14.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rewrites the preflight and INVOCATION.md prompts to enumerate three legitimate implementation modes instead of a binary port-or-Issue choice.
Three modes Direct port — implement the paper’s method as-described. Requires the repo to host the paper’s full infrastructure. Adapted port — implement the paper’s core mechanism at full fidelity while substituting auxiliary components (learned estimators, bespoke optimizers, benchmark suites) with target-native equivalents (parameter-free proxies, existing library functions, scope cuts). Inspired experiment — take the paper’s core insight or framing and implement a target-native experiment drawing on it. The PR applies the paper’s idea rather than reproducing its method. Route to Issue only when all three modes fail. The coding session’s self-review must cite which mode was used and, for Modes 2/3, name the specific substitutions or reframed insight.
July 10, 2026
MCPShield MCP Config Scan
Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new PR-comment mode (comment: true): posts a sticky findings comment on the pull request, updated in place on each run (never duplicated). Requires permissions: pull-requests: write. Stdlib-only and best-effort — a comment failure logs a warning but never fails the build. Usage: https://github.com/RunTimeAdmin/mcpshield-action#comment-on-the-pull-request
July 10, 2026
create-agent-room Validate
Version updated for https://github.com/sipandey/create-agent-room to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed create-agent-room v2.1.0 The headline of this release is a new doctor command — a read-only health check for your agent room — plus a CI safeguard against a lockfile-drift bug that bit us twice. No breaking changes; this is a clean drop-in upgrade from 2.0.x.
July 10, 2026
GitGalaxy Scanner
Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Internal infrastructure release to verify the automated GitHub Actions to GitLab component catalog mirroring pipeline.
July 10, 2026
Setup cloudflared tunnel
Version updated for https://github.com/var-template/setup-cloudflare-tunnel to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/var-template/setup-cloudflare-tunnel/commits/v1.0.0
July 10, 2026
latex2arxiv pre-flight
Version updated for https://github.com/YuZh98/latex2arxiv to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Demo document now states its own run’s numbers correctly (file counts, warning count, page count, before/after size, title-dedup wording) and mentions \addbibresource in the dependency-tracking list
July 9, 2026
probelock gate
Version updated for https://github.com/kelkalot/probelock to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add trace pipeline validation and recorder by @kelkalot in https://github.com/kelkalot/probelock/pull/4 Add trend command for N-way lockfile analysis by @kelkalot in https://github.com/kelkalot/probelock/pull/5 Add json_mode, OTEL/Anthropic ingest, embeddings by @kelkalot in https://github.com/kelkalot/probelock/pull/6 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v0.4.0
July 9, 2026
Kusari Ingest
Version updated for https://github.com/kusaridev/kusari-ingest to version v4.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed update kusari cli to version 2.6.0 by @pxp928 in https://github.com/kusaridev/kusari-ingest/pull/34 Full Changelog: https://github.com/kusaridev/kusari-ingest/compare/v4...v4.2.0
July 9, 2026
Langfuse Experiment
Version updated for https://github.com/langfuse/experiment-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs: pin README examples to v1.0.5 by @github-actions[bot] in https://github.com/langfuse/experiment-action/pull/68 chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/69 ci(deps): Bump the github-actions group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/70 chore(deps-dev): Bump the npm group with 3 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/71 chore(deps-dev): Bump vite from 8.0.16 to 8.1.0 in the npm group by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/72 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/73 ci(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 in the github-actions group by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/75 chore(deps): Bump the npm group with 4 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/74 chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/76 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/77 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/79 fix(comment): stop parallel matrix legs from clobbering each other’s PR comment sections by @wochinge in https://github.com/langfuse/experiment-action/pull/80 Full Changelog: https://github.com/langfuse/experiment-action/compare/v1.0.5...v1.0.6
July 9, 2026
Gua Godot GDScript CI
Version updated for https://github.com/link1345/gua-tester to version v1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/link1345/gua-tester/compare/v1.1...v1.2
July 9, 2026
Setup Go Android Environment
Version updated for https://github.com/nostalgia296/setup-go-android to version v3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 提交 (51d281b)
July 9, 2026
ObsidianWall Verdict
Version updated for https://github.com/ObsidianWall/obsidianwall-verdict to version v0.5.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ObsidianWall Verdict v0.5.2 Verdict becomes a governance decision engine — not just a policy checker.
What’s New verdict explain — Full Reasoning on Demand Terminal output from verdict evaluate is now a concise ~15-line summary by default. Full governance reasoning, condition traces, analyzer findings, and recommendations are one command away:
July 9, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.38.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Scoped / least-privilege identity execution-context signal (ST-AUTH-SCOPED, ruleset 41). A new scanner detects short-lived, scoped, assumed identities — STS AssumeRole / session tokens, cloud managed / workload identity, impersonated service accounts, projected Kubernetes service-account tokens, dynamic-secret brokers — and surfaces them as the scoped_identity trait (CSA “Tool Execution Context / Least-Privilege Service Identity”). This completes the execution-context dimension: embedded_credential (Agent Service Identity, largest blast radius) → delegated_authentication (User Delegated Credentials) → scoped_identity (least privilege, smallest). Neutral capability finding (0-score); adds Capability.SCOPED_IDENTITY. Scored detection is unchanged (efficacy 100% recall / 0 FP). See RULES_CHANGELOG.md.
July 9, 2026
PY Modbus Test Suite
Version updated for https://github.com/php-modbus/py-modbus-test-suite to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 — 2026-07-07 Initial Release Docker-based Modbus server simulator suite for testing Modbus clients and SCADA systems, built on pymodbus (pinned 3.13.1).
Server Infrastructure 6 pre-configured endpoints via Docker Compose from a single image: Modbus TCP (host port 502), RTU over TCP (5021), ASCII over TCP (5022), UDP (5023), Modbus/TCP Security TLS (host port 802), RTU on virtual serial via RFC2217 (5024, raw 5025). Non-root container — binds unprivileged in-container ports (5020+); canonical 502/802 come from host port mappings. Health check via python -m mbsim.healthcheck — reads hr[0] of the health device (unit 1, expected 1234), so docker compose up --wait gates on real Modbus readiness. Baked-in config and certs — GitHub Actions service containers cannot mount checkout files; override at runtime with MBSIM_MAP_B64 / MBSIM_SCENARIO_B64 or a volume on /app/config. Register Map & Generators YAML register map (config/default-map.yaml) defining units 1–3 with holding registers, input registers, coils and discrete inputs; multiple devices entries simulate a multi-drop bus behind one endpoint. 4 deterministic generators — ramp, sine, random_walk, toggle: tick-based, seeded per cell from the map seed — same map, same history, every run. Fault Injection Scenario YAML (config/scenarios/*.yaml) attaching deterministic faults per rule; matchers device_id, function_code, every_nth, after_n_requests, times — counting is request-order based, never wall clock. 7 fault actions — exception, no_response, truncate, corrupt (CRC/LRC/MBAP), garbage, delay, disconnect. 7 pre-configured fault services behind the faults compose profile (ports 5100–5106): tcp-silent, tcp-slow, tcp-exceptions, tcp-drop, rtu-tcp-badcrc, tcp-truncated, tcp-garbage. Health-safety guard — rules that could hit holding-register reads on the health device are rejected at startup. CI/CD GitHub Actions composite action (action.yml) for one-step CI integration — inputs services, faults, wait-timeout; output certs-dir for TLS CA pinning. Docker image published to ghcr.io/php-modbus/py-modbus-test-suite (multi-arch amd64/arm64) by .github/workflows/release.yml, gated on the smoke suite. CI-optimized compose file (docker-compose.ci.yml) with no-restart policy. Documentation Documentation in docs/ covering setup, endpoints, register map, generators, fault injection, environment variables, serial usage, and CI integration.
July 9, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.32.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Ships litmus-v15: the C-02 egress baseline now includes public package-registry infrastructure (pypi.org, files.pythonhosted.org, registry.npmjs.org), so a framework’s default startup update-check — chiefly FastMCP pinging pypi.org for a newer version — is no longer scored as the server’s egress overreach. The cloud instance-metadata endpoint stays flagged (a real credential-theft target).
July 9, 2026
Build & Push to Registry
Version updated for https://github.com/relybytes/actions-docker-build-push to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/relybytes/actions-docker-build-push/compare/v1.0.0...v1.0.1
July 9, 2026
spec.md check
Version updated for https://github.com/rosenjcb/spec.md to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #4 from rosenjcb/claude/spec-signoff-feedback-9ei975 (72589a5) Triage moves to the front of the skill; distribution stays manual (4891b3c) Teach the skill and commands the review lifecycle (7222102) Review records become OKF documents; approval state moves to the review (05e082e) Per-stakeholder briefings replace generic section links (dd9b819) Scope each reviewer’s reading with a Read column of deep links (e53ca5d) Replace prior-art essay with a further-reading appendix (b78a6e4) De-emphasize DACI: name it once, drop the framework comparison (cef6e39) Purge comma-splitting from frontmatter parsing (ab840ae) Purge all mentions of comma-separated frontmatter strings (4e9aa2c)
July 9, 2026
Podcast Generator by Russel Tjahjadi
Version updated for https://github.com/russeltjahjadi/podcast-generator to version v.10.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/russeltjahjadi/podcast-generator/commits/v.10
This is a project that I have been following along by Ray Villalobos
July 9, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.30.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added MD007: clamp explicit fixed-style indent under ordered parents (1f3a32d) Fixed lint-context: keep lazy continuation lines in their list block (a17f0af) Downloads File Platform Checksum rumdl-v0.2.30-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.30-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.30-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.30-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.30-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.30-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.30-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
July 9, 2026
memi design CI
Version updated for https://github.com/sarveshsea/memi to version v2.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights GitHub Action Marketplace-ready: action.yml description shortened to 122 characters (Marketplace ≤125 limit). Branding: layout / purple. CLI pin: Action default version installs published @memi-design/cli@2.4.0 (npm 2.4.1 publish is blocked on registry auth — package metadata in-repo is already 2.4.1). Grok Build (Grok 4.5): memi agent install grok-build writes native .grok/config.toml + .grok/skills/ (plus .agents/skills/ mirror). Skills ecosystem: agent-first packaging patterns adapted from emilkowalski/skills with explicit craft-skill dependency links (no content copy). Marketplace publish (manual UI step remaining) gh cannot set Marketplace categories. Finish here:
July 9, 2026
JS Recon
Version updated for https://github.com/shriyanss/js-recon-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Publish action on GitHub marketplace
July 9, 2026
create-agent-room Validate
Version updated for https://github.com/sipandey/create-agent-room to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/sipandey/create-agent-room/compare/v1.3.1...v2.0.1
July 9, 2026
Snowflake Flow Diff
Version updated for https://github.com/Snowflake-Labs/snowflake-flow-diff to version v0.0.24.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Configure Dependabot for Maven in flow-diff directory by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/62 Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64 Bump org.apache.nifi:nifi-api from 2.6.0 to 2.7.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/65 Bump jackson.version from 2.21.1 to 2.21.2 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/67 Bump org.apache.nifi:nifi-api from 2.7.0 to 2.8.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/68 Bump nifi-framework.version from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/69 Bump jackson.version from 2.21.2 to 2.21.3 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/70 Bump org.slf4j:slf4j-nop from 2.0.17 to 2.0.18 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/71 Bump junit.version from 6.0.3 to 6.1.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/72 Bump jackson.version from 2.21.3 to 2.22.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/73 Bump org.apache.nifi:nifi-api from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/74 Bump junit.version from 6.1.0 to 6.1.1 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/80 Group diff output by process group by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/76 Adding support for checkstyle rules to enforce naming conventions by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/66 Bump nifi-framework.version from 2.9.0 to 2.10.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/79 Detect duplicate JSON keys in flow files by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/78 New Contributors @dependabot[bot] made their first contribution in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64 Full Changelog: https://github.com/Snowflake-Labs/snowflake-flow-diff/compare/v0...v0.0.24
July 9, 2026
Snowflake Actions
Version updated for https://github.com/snowflakedb/snowflake-actions to version v3.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Snowflake Actions v3.1.0
New Cortex Code and DCM composite actions, a shared-script install foundation, and auth-type telemetry.
Highlights Cortex Code action (cortex-code/): install the Cortex Code (CoCo) CLI and auto-configure a connection from the parent action’s OIDC flow. (#12, #15) DCM composite actions (dcm/): parse-manifest, connection-test, plan, and deploy for building Snowflake DCM CI/CD pipelines, with color-coded plan summaries and PR comments. (#19, #20) snowflake-cli leaf action + shared scripts/: install / OIDC-minting / env-setup logic extracted into reusable scripts, sourced from a single-source VERSION file. (#14, #15) Auth-type telemetry: SF_CICD_AUTH_TYPE=oidc exported when use-oidc is enabled, so the CLI records which auth type this action configured. (#10) Docs Improved README intro, OIDC example, and how-it-works; documented the DCM actions and env-var vs config.toml auth. (#8, #9) Usage: uses: snowflakedb/snowflake-actions@v3
July 9, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.7.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.
July 9, 2026
Deploy to Vercel
Version updated for https://github.com/Spectra010s/d-vercel to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed d-vercel v1.0.0 Initial release of d-vercel — a GitHub Action for deploying projects to Vercel directly from GitHub Actions.
Features Deploy to Vercel from GitHub Actions workflows Support preview and production deployments Configure Vercel organization and project IDs Automatically capture deployment URLs Add/update deployment comments on pull requests Customizable deployment options Usage See the README.md for setup instructions and workflow examples.
July 9, 2026
rsync action
Version updated for https://github.com/spotdemo4/rsync-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump: v0.0.2 -> v0.1.0 (387847b) feat(action): remove local path after successful post-job push (00f83f5) ci(checks): switch workflows to nix-init and codex cli (c18267b) ci(workflow): add codex action step to check pipelines (a8db651) build(flake): drop rsync override and refresh lock inputs (cdd7044) chore(deps): update spotdemo4/nix-init action to v1.56.0 (#6) (658c8c5) chore(deps): update dependency @types/node to ^24.13.3 (#5) (6704097) chore(deps): lock file maintenance (#4) (25a86a5) chore(deps): update spotdemo4/nix-init action to v1.55.0 (#3) (918d77e) docs(readme): refresh badges and trim rsync README text (fd21ad0)
July 9, 2026
Downstream Breakage Radar
Version updated for https://github.com/Tahiram32/downstream-breakage-radar to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Enterprise Upgrade (v0.5.0) 🚀 This major update adds powerful compliance, customization, and deprecation lifecycle controls for developers and organizations.
🌟 New Features ⚠️ Deprecation Checker — When a public function or class is removed, the tool checks the base branch to see if it was marked with a deprecation warning first. Pre-deprecated removals are downgraded to medium severity; surprise removals stay high. 🛡️ SARIF Output (--format sarif) — Export results in standardized SARIF JSON format for integration with GitHub’s native Security / Code Scanning dashboard. 📝 API Changelog Generator (--changelog) — Generates a clean breakage-radar-changelog.md listing every public addition, removal, and signature change across Python, Go, and JS/TS files. ⚙️ In-Manifest Configuration — Configure ignored paths, public directories, and severity overrides directly inside pyproject.toml or a breakage-radar.json file — no CLI flags required. 📦 Install / Upgrade pip install --upgrade downstream-breakage-radar 🔧 Usage - name: Scan for breaking changes uses: Tahiram32/downstream-breakage-radar@v0.5.0 with: base-ref: origin/main format: markdown fail-on: high changelog: true 📄 Docs Full documentation and configuration reference: https://tahiram32.github.io/downstream-breakage-radar/
July 9, 2026
tmas-scan
Version updated for https://github.com/trendmicro/tmas-scan-action to version v3.2.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Security hardening of TMAS binary download.
Note: New dependency required for GitHub Action runner environments
sha256sum (from GNU coreutils) or shasum
July 9, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.709.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.709.2 Released 2026-07-09
This release of the Vibgrate CLI introduces significant improvements to the search_symbols command and enhances the vg serve functionality. Performance optimizations have also been implemented for better efficiency in large repositories.
July 9, 2026
Install Zig
Version updated for https://github.com/xyzzylabs/setup-zig to version v1.0.2.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-09) Fixed deps: bump @actions/cache to 6.1.0 to resolve undici advisory (#7) (ed5b607) Documentation correct README claim that dist/ is not committed (#3) (81642f2)
July 9, 2026
GHCR Cleanup Manager
Version updated for https://github.com/ghcr-manager/ghcr-cleanup-manager to version v1.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the github-actions group with 4 updates by @dependabot[bot] in https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/8 Bump the npm group across 1 directory with 6 updates by @dependabot[bot] in https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/9 Full Changelog: https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.5...v1.1.6
July 9, 2026
Create contributors list
Version updated for https://github.com/gouef/create-contributors-action to version v1.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.5...v1.0.6
July 9, 2026
Run go tests and upload coverage
Version updated for https://github.com/gouef/go-test-with-coverage-action to version v1.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.2...v1.0.3
[Upgrade] actions/checkout and actions/setup-go versions [ 524280e ] (@JanGalek)[Update] Automate update contributors [ 761b00c ] (@actions-user)
July 9, 2026
Create Release Note with PRs, Issues, Users
Version updated for https://github.com/gouef/release-action to version v1.0.2.
This action is used across all versions by 63 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.1...v1.0.2
[Update] checkout action to version 6 [ 45f3bf5 ] (@JanGalek)[Update] Automate update contributors [ 533f304 ] (@actions-user)
July 9, 2026
action-lambda-publish
Version updated for https://github.com/heronlabs/action-lambda-publish to version v3.0.12.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v3.0.12 (0657d06) chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda) [skip ci] bump v3.0.11 (d90741b) chore(deps): bump the actions group across 1 directory with 3 updates (#18) (111bfbe) [skip ci] bump v3.0.10 (6ea8ec3) Add branding icon and color to action.yml (c79ecda) [skip ci] bump v3.0.9 (ce780a2) docs: standardize README badges and add repo-specific CLAUDE.md (#17) (13f3b58) [skip ci] bump v3.0.8 (eea976e) chore: standardize action pipeline, architecture, and step names (964097b)
July 9, 2026
OpenBSD Action
Version updated for https://github.com/ivoronin/openbsd-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First marketplace release of openbsd-action.
This action runs one GitHub Actions command inside an OpenBSD VM. It downloads a pre-built OpenBSD image from ivoronin/openbsd-cloudimg releases, verifies its GitHub attestation, boots it with QEMU, syncs the workspace into /home/openbsd/work, runs your command, then syncs the workspace back even if the command exits non-zero.
July 9, 2026
Kura Pages
Version updated for https://github.com/kurajs/pages to version v1.0.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Retire the sed link pre-fix: native resolution (kura >=0.0.27, docs >=0.0.50) covers every class it handled plus everything it structurally could not (anchors, ../../ escapes, subfolder docs, pruned targets, code-span link text, non-.md files), with exact-sha blob URLs and a never-guess git-tracked oracle. Verified live on rustbgpd: 132/132 docs covered, 146 oracle targets, zero dead relative links site-wide.
July 9, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [6.1.0] — 2026-07-08 Added Taint-aware demotion engine: pattern-only findings with no taint trace are now demoted from HIGH/CRITICAL to MEDIUM at most. CWE-617/200/532 (code-quality rules) are always LOW. CWE-798 (hardcoded secrets) is exempt. _HARDCODED_DEMOTE_CWES and _NO_TRACE_DEMOTE_CWES constants in CLI post-processing pipeline Changed HIGH/CRITICAL precision: 0% → 19.1% across 43 repos Findings/file: 3.1 → 1.7 (default filter) CWE-617 (silent exceptions) severity: HIGH → LOW CWE-117 (log injection) without user input: CRITICAL → LOW CWE-89/78/1188/352/601 without taint trace: HIGH → MEDIUM Verified 43 repos scanned, 4,114 findings, 1,075 HIGH/CRIT → 205 suspected real 1 confirmed real vulnerability (CWE-601 open redirect via request.referrer) 1,249 tests pass, 0 regressions Noise gate CI: 0% HIGH/CRIT false-negative guarantee maintained
July 9, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.94.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(docs): repair out-of-tree links breaking strict mkdocs build by @msaad00 in https://github.com/msaad00/agent-bom/pull/3632 fix(cli): unified terminal UX — sections, deduped CIS, quiet cloud by @msaad00 in https://github.com/msaad00/agent-bom/pull/3633 fix(cloud): Key Vault CIS false-PASS + least-privilege deep-scan grants by @msaad00 in https://github.com/msaad00/agent-bom/pull/3636 fix(cloud): scan Lambda deployment packages + deep-scan pre-tagged container images by @msaad00 in https://github.com/msaad00/agent-bom/pull/3634 fix(cloud): Lambda discovery on by default (no –include-lambda) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3635 ci(docs): gate PRs on mkdocs build –strict by @msaad00 in https://github.com/msaad00/agent-bom/pull/3638 feat(output): scale-ready tabbed + paginated HTML report by @msaad00 in https://github.com/msaad00/agent-bom/pull/3637 feat(ui): Storybook harness for large dashboard components by @msaad00 in https://github.com/msaad00/agent-bom/pull/3640 feat(enrich): mature the multi-provider LLM enrichment harness by @msaad00 in https://github.com/msaad00/agent-bom/pull/3639 fix(scanners): correct OSV fixed_version resolution by @msaad00 in https://github.com/msaad00/agent-bom/pull/3644 fix(output): SARIF/json finding-count parity + –reproducible timestamps + /dev/null exit by @msaad00 in https://github.com/msaad00/agent-bom/pull/3645 Part of #1469 (Phase 0: hardware-backed device identity) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3646 chore: logo + branding consistency pass by @msaad00 in https://github.com/msaad00/agent-bom/pull/3647 Part of #3499 (Iceberg catalog export) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3648 Part of #3499 (ClickHouse findings-ingest) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3650 perf(db): fix cvss filesort + O(table) origin count on hub current reads by @msaad00 in https://github.com/msaad00/agent-bom/pull/3654 Part of #3192 (drift-as-UI lens) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3649 Part of #1969 (phase 1: strict mypy for models + core API) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3655 Closes #3499 tail (Swift bare-call precision) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3656 perf(db): generic RANGE-partition maintenance + retention rollover by @msaad00 in https://github.com/msaad00/agent-bom/pull/3657 fix(rbac): resolve NO_AUTH_ROLE from env at call time (kills release-blocker CI flake) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3660 docs: canonical how-it-works + deployment matrix + editions page by @msaad00 in https://github.com/msaad00/agent-bom/pull/3668 fix(api): consistent empty-scan response shape across MCP and HTTP surfaces (CI flake) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3663 Closes #1522 (split output/html.py) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3661 perf(graph): bounded snapshot-stats, rollup orphans, deep-offset cap (Part of #3664) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3669 refactor(cli): unify scan verb, tier flags behind –help-all, dedup formats by @msaad00 in https://github.com/msaad00/agent-bom/pull/3672 fix(cis): fail-closed on per-resource permission denial across ~25 checks (Closes #3679) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3691 fix(mcp): gate ingest_external_scan as a destructive write (Closes #3681) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3692 fix(ingest): chunked reconcile_absent + pip-visible ai-enrich security floors by @msaad00 in https://github.com/msaad00/agent-bom/pull/3693 fix(cis): ERROR on partial permission denial (strict GRC coverage) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3695 fix(malicious): synthesize vuln-less malicious findings end-to-end by @msaad00 in https://github.com/msaad00/agent-bom/pull/3694 fix(audit): genesis chain verification and git-SHA range false-positive by @msaad00 in https://github.com/msaad00/agent-bom/pull/3696 feat(runtime): shield fail-closed defaults, cred redact, SSRF guard by @msaad00 in https://github.com/msaad00/agent-bom/pull/3699 feat(audit): signed chain checkpoint detects tail truncation by @msaad00 in https://github.com/msaad00/agent-bom/pull/3700 feat(identity): SCIM patch fixes, audit RBAC, session logout hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3701 chore(dev): ‘make preflight’ to catch OpenAPI/schema drift before push by @msaad00 in https://github.com/msaad00/agent-bom/pull/3702 docs: consolidate duplicate doc clusters (stage 1 of #3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3704 feat(identity): auto-bind SCIM subject on API key issuance by @msaad00 in https://github.com/msaad00/agent-bom/pull/3705 feat(platform): DB-aware /readyz and firewall reload fail-closed by @msaad00 in https://github.com/msaad00/agent-bom/pull/3707 feat(cloud,runtime): full coverage and shield hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3706 fix(config): warn on unparseable env bool/int/float values by @msaad00 in https://github.com/msaad00/agent-bom/pull/3711 feat(output): add SARIF partialFingerprints for GitHub dedup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3712 docs(config): canonical env aliases and regenerated ENV_VARS (#3677) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3713 refactor(api): centralize /v1 mount on shared API router (#3666) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3715 chore(tests): group cloud tests under tests/cloud/ (#3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3716 fix(security): resolve CodeQL sensitive export and exception alerts by @msaad00 in https://github.com/msaad00/agent-bom/pull/3717 chore(tests): group API tests under tests/api/ (#3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3718 fix(security): clear CodeQL alerts and finalize MCP catalog drift (#3675) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3719 docs(deploy): add README for raw Kubernetes manifests by @andres-linero in https://github.com/msaad00/agent-bom/pull/3720 docs(deploy): add README for Snowflake deployment assets by @andres-linero in https://github.com/msaad00/agent-bom/pull/3721 chore(release): prepare 0.94.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3722 fix(accuracy): git-SHA advisory false positives + malicious packages missing from CSV by @msaad00 in https://github.com/msaad00/agent-bom/pull/3723 docs(release): fold #3723 into 0.94.0 changelog by @msaad00 in https://github.com/msaad00/agent-bom/pull/3724 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.93.5...v0.94.0
July 9, 2026
Setup atago
Version updated for https://github.com/nao1215/setup-atago to version v0.1.1.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed fix: a successful install no longer exits nonzero (the EXIT-trap cleanup referenced an out-of-scope local under set -u, failing every green run at the very end) docs: drop the “atago is unreleased” warning — atago v0.1.0 is published and this action now installs it The floating v0 tag points at this release. Verified end-to-end against the real v0.1.0 release: checksum, SLSA attestation (gh attestation verify), install, and atago version / init / run.
July 9, 2026
Lambda MicroVM GitHub Runner
Version updated for https://github.com/neebs12/lambda-microvm-github-runner to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/neebs12/lambda-microvm-github-runner/commits/v1
July 9, 2026
XAI Review
Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.69.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed azure openai (978e700) Merge pull request #99 from crow-ua/add-support-for-gpt-5-max-complete-tokens (e28ac59) renamed files (61d7b2b) bitbucket server (1bbc1d8) openai stream (da6aabb) ripgrep (ffd969f) Add support for max_completion_tokens in Azure OpenAI schemas and client for GPT-5 models (185b557) up version (e553e3c) Merge pull request #90 from crow-ua/fix-azure-devops-ai-comments (f20fdf6) Removing hidden state dependency (971ff32)
July 9, 2026
OpenShock Release Tool
Version updated for https://github.com/OpenShock/release-tool to version v0.3.0.
This action is used across all versions by 0 repositories. Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Bump actions/cache from 4.3.0 to 6.1.0 in the github-actions dependency group Contributors Thanks to @hhvrc for contributing to this release!
July 9, 2026
Set up AAPT2
Version updated for https://github.com/OussamaTeyib/setup-aapt2 to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update dependency @types/node to v25.9.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/13 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/14 Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/15 Remove redundant platformAutomerge option by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/17 Update npm to v11.16.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/18 Add CodeQL static analysis workflow by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/19 Update dependency @types/node to v25.9.2 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/20 Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/21 Update dependency @types/node to v25.9.3 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/22 Update npm to v11.17.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/23 Update actions/checkout action to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/24 Update dependency @types/node to v25.9.4 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/25 Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/26 Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/27 Update dependency @types/node to v26.0.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/28 Update npm to v11.18.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/29 Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/30 Update dependency @types/node to v26.1.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/31 Update dependency @types/node to v26.1.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/32 Update npm to v12 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/34 Migrate to esbuild by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/35 Update dependency typescript to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/33 Full Changelog: https://github.com/OussamaTeyib/setup-aapt2/compare/v1.0.1...v1.0.2
July 9, 2026
Set up Android Manifest Merger
Version updated for https://github.com/OussamaTeyib/setup-manifest-merger to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update dependency @types/node to v25.9.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/9 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/10 Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/11 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/12 Update npm to v11.16.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/13 Add CodeQL static analysis workflow by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/14 Update dependency @types/node to v25.9.2 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/15 Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/16 Update dependency @types/node to v25.9.3 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/17 Update npm to v11.17.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/18 Update actions/checkout action to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/19 Update dependency @types/node to v25.9.4 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/20 Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/21 Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/22 Update dependency @types/node to v26.0.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/23 Update npm to v11.18.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/24 Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/25 Update dependency @types/node to v26.1.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/26 Update dependency @types/node to v26.1.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/27 Migrate to esbuild by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/29 New Contributors @dependabot[bot] made their first contribution in https://github.com/OussamaTeyib/setup-manifest-merger/pull/21 Full Changelog: https://github.com/OussamaTeyib/setup-manifest-merger/compare/v1.0.2...v1.0.3
July 9, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.36.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Declarative combination registry (skilltotal/combinations.py). The four synthesized combination findings — emergent risk from co-occurring signals (ST-COMBO-EXFIL, ST-FLOW-TRIFECTA, ST-INSTALL-DROPPER, ST-CONVERGENCE) — are now declared in one ordered registry, each with a short technique label (for the public per-technique benchmark) and an evaluator adapter. The engine iterates the registry in two phases (pre-/post-threat-class assignment) instead of four hardcoded calls, so a new combination is a registry entry, not an edit to the engine’s control flow. Behavior is byte-identical — the calibrated detection logic stays in scoring.py, guarded by the recall gate and the per-finding golden set; RULESET_VERSION (39) and the report shape (schema 1.5) are unchanged. Each combination id is kept in sync with its RuleSpec and ComponentTrait by tests/test_combinations.py.
July 9, 2026
OpenTelemetry for GitHub Workflows, Jobs and Steps
Version updated for https://github.com/plengauer/Thoth to version v5.58.1.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Re-disable slim images temporarily while network is still restricted by @plengauer in https://github.com/plengauer/Thoth/pull/3715 Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 (#3705) by @plengauer in https://github.com/plengauer/Thoth/pull/3714 Automatic Version Bump by @plengauer in https://github.com/plengauer/Thoth/pull/3719 Full Changelog: https://github.com/plengauer/Thoth/compare/v5.58...v5.58.1
July 9, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.1
July 9, 2026
GitHub-Script (by PSModule)
Version updated for https://github.com/PSModule/GitHub-Script to version v1.9.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 28 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 [Feature]: Version input accepts NuGet version ranges (#98) The Version input now accepts a NuGet version range in addition to an exact version, so a workflow can pin a compatible window (for example [1.2.0, 2.0.0)) instead of a single build. Pinning an exact version keeps working exactly as before, and a version that is already installed and satisfies the request is no longer reinstalled on every run.
July 9, 2026
Pipeline Pling
Version updated for https://github.com/Qbox-project/pipeline-pling to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Pipeline Pling v1.1.0 Adds two new ways to control which pushes and commits get posted to Discord.
Silent commits Exclude specific commits from notifications by putting !silent on the first line of the commit body:
July 9, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.13.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Follow-up to v1.7.12. The PDF-text discovery path shipped in v1.7.12 depended on pdftotext, which turned out not to be installed on ubuntu-latest runners as of mid-2026 — the fallback fired but silently returned empty. This release makes it actually work.
July 9, 2026
SignalEDI Convert EDI to JSON
Version updated for https://github.com/SignalEDI/edi-to-json to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial Marketplace release.
July 9, 2026
MCP Trust Scan
Version updated for https://github.com/SteveMonsway/mcp-trust to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One-line MCP-server preflight scan in CI — the root composite Action.
```yaml
uses: actions/checkout@v4 uses: SteveMonsway/mcp-trust@v1 with: { fail-on: high, upload-sarif: true, comment-pr: true } ``` Runs the published @mcp-trust/cli via `npx` (self-contained, no build). Uploads SARIF to Code Scanning, posts a PR comment, and fails the job above a severity threshold.
July 9, 2026
LLM Prompt Radar
Version updated for https://github.com/Tahiram32/llm-prompt-radar to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s New in v0.2.0 YAML/TOML config file support (.promptradar.yml) LangChain and LlamaIndex SDK support Custom rule definitions (bring-your-own regex) PR comment posting with risk summary table Pre-commit hook integration VS Code extension skeleton pip install --upgrade llm-prompt-radar PyPI: https://pypi.org/project/llm-prompt-radar/0.2.0/
July 9, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.18.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.18.0 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/35 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.3...v0.18.0
July 9, 2026
latex2arxiv pre-flight
Version updated for https://github.com/YuZh98/latex2arxiv to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Pre-flight warns when a shipped .bbl has a bbl format version arXiv won’t accept (3.2 needs the soon-to-retire TL2023; anything else needs regeneration), when a BibTeX-format .bbl is paired with a biblatex document, and when a bundled biblatex.sty is included in the submission Changed Citation scan now recognizes the biblatex cite families (\autocite, \parencite, \textcite, \footcite, \nocite, capitalized and multicite forms) and pre/post-note optional arguments; the undefined-citation check reads biblatex-format .bbl files (\entry{...}) in addition to \bibitem Fixed \addbibresource[options]{...} is now recognized by dependency tracking, pre-flight, and the --compile biber dispatch; the functional biblatex keywords field is no longer stripped from .bib files in biblatex projects VS Code extension (0.1.2): the new biblatex pre-flight warnings are located in the editor — .bbl format/backend warns anchor the .bbl file itself, the bundled-biblatex.sty warn anchors the .sty Dependency tracking resolves \input/\include in nested files against the compile root (LaTeX semantics) and keeps non-.tex targets such as .pgf figures; both were previously pruned from the output (#229) Custom config rules no longer match longer commands sharing a prefix (an hl rule used to corrupt \hline) (#229) The hidden-file pre-flight warning is emitted once per dot-directory instead of once per contained file (#229)
July 8, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.10.0 (2026-07-08) GitLost-class agentic-workflow posture detection
Closes the gap surfaced by Noma Security’s “GitLost” disclosure (July 2026): an AI agent driven by a GitHub workflow can be prompt-injected through an untrusted issue/PR into leaking private-repo data via a public comment. The runtime attack is GitHub’s to fix; what is static and checked-in is the vulnerable POSTURE, and that is now scannable before an attacker files the issue.
July 8, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: add A2A protocol security support (v2.6.0) (1b99a1b) fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688) chore: replace all example.com targets with simpleportchecker.com (676106d) fix: –format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8) fix: skip –timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd) chore: use Gemini public endpoint in ai-owasp-scan job (6a13857) fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41) fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327) chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12) fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)
July 8, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.4
July 8, 2026
MLX Model Doctor
Version updated for https://github.com/IonDen/mlx-model-doctor to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Prepare v0.7.0 reach/readiness and VLM plugin release by @IonDen in https://github.com/IonDen/mlx-model-doctor/pull/23 Full Changelog: https://github.com/IonDen/mlx-model-doctor/compare/v0.6.2...v0.7.0
July 8, 2026
🚀 React Template CI/CD
Version updated for https://github.com/Jagoda11/react-template to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add Claude Code setup: CLAUDE.md + .claude/settings.json with permissions, hooks, plugins Rename lint step in npm-upgrade workflow (drop misleading “non-blocking” label) Compatibility Node 24.x ESLint 9.x
July 8, 2026
Official Junie GitHub Action
Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Junie]: Update Junie CLI Version to 2144.8 in Files by @mashan555 in https://github.com/JetBrains/junie-github-action/pull/174 Full Changelog: https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.8
July 8, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.9.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.0
July 8, 2026
jscpd-copy-paste-detector
Version updated for https://github.com/kucherenko/jscpd to version v5.0.12.
This action is used across all versions by 4,427 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Bug Fixes Rename cpd binary and npm packages to jscpd — the CLI binary was named cpd (cpd.exe on Windows), which collided with an executable name flagged by some antivirus software (McAfee, Trend Micro), causing false-positive blocking. The binary and platform npm packages are now named jscpd / jscpd-*. Closes #826 (#854) Recognize ; line comments for Lisp/Clojure/Scheme/Racket — these languages fell through to C-style comment handling, so ; comments were tokenized as code and --mode weak / --skip-comments couldn’t drop them. Closes #849 (#850, thanks @laurynas-biveinis) Use HTTPS for SARIF schema URI — avoids “untrusted URI” errors in SARIF-consuming tools (#844, thanks @chrisc-onaorg) Chores Use public repository URLs for @jscpd/core, @jscpd/finder, @jscpd/tokenizer, @jscpd/html-reporter, @jscpd/badge-reporter, @jscpd/leveldb-store, and @jscpd/redis-store package metadata (#831–#837, thanks @9904099) Add cargo ecosystem to Dependabot config Dependencies Bump askama to 0.16.0 in /rust Bump log to 0.4.33 in /rust Bump env_logger to 0.11.11 in /rust Bump rustc-hash to 2.1.3 in /rust Thanks Big thanks to @laurynas-biveinis, @chrisc-onaorg, and @9904099 for their contributions to this release! 🙌
July 8, 2026
GitHub Contributor Summary
Version updated for https://github.com/kurehajime/contributor-summary to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1st Release
July 8, 2026
CA Certificate Import
Version updated for https://github.com/LiquidLogicLabs/git-action-ca-certificate-import to version v3.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 📦 Uncategorized chore: standardize tooling to current playbook chore(release): 3.0.3 Pull Requests #{{PR_LIST}}
Usage - uses: LiquidLogicLabs/git-action-ca-certificate-import@v3.0.3 with: certificate: 'path/to/cert.crt' # Auto-detects: file path, URL, or inline content Installation The certificate will be installed to the system CA store and trusted by:
July 8, 2026
conventional-semver
Version updated for https://github.com/logi-camp/conventional-semver to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bug Fixes: BREAKING CHANGE detection in changelog: Fixed an issue where BREAKING CHANGE: footers in commit bodies were not being included in the generated changelog output. Breaking changes are now properly surfaced.
July 8, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v6.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [6.0.0] — 2026-07-08 Added Rust language analyzer (RS-001–006): CWE-119 (unsafe blocks), CWE-798 (hardcoded credentials), CWE-78 (command injection), CWE-327 (weak crypto), CWE-532 (sensitive panics), CWE-362 (TOCTOU) LSP code actions + hover: VS Code now offers one-click fix suggestions via the lightbulb (codeAction) and vulnerability details on hover Live playground at /scan: paste code, see findings — no install required. Available at ansede.onrender.com/scan GitLab CI + Azure DevOps + Jenkins templates in docs/ci-templates/ Adaptive Rules section in README — --suggest documented prominently --all-findings flag: escape hatch to see all findings regardless of confidence Random-repo noise-gate CI: validates 0% HIGH/CRIT false-negative rate on every release fast/full/enterprise extras in pyproject.toml for friendlier optional-dependency names Changed Confidence threshold default: 0.0 → 0.65 — scans now filter low-signal findings by default. CRITICAL/HIGH findings are never suppressed regardless of confidence. Use --all-findings to see everything. post-pr-comments default: false → true in GitHub Action — PRs now get inline security review comments by default Confidence score displayed in text output for findings < 80% confidence OWASP recall badge: 93.3% (unchanged, confirmed) Language count: 5 → 6 (added Rust) Test count: 1,234 → 1,249 Measured Impact (fresh random repos) HIGH/CRITICAL findings lost: 0 out of 790 across 5 diverse codebases Noise reduction: 5–41% depending on codebase maturity (average ~22%) Zero regressions; all 1,249 tests pass Competitive Position (July 2026) #1 CVE Recall: 100% (164/164 across 5 languages) #1 OWASP Recall: 93.3% #2 OWASP Youden Score: +0.8% #1 Language Breadth: 6 languages (Python, JS/TS, Go, Java, C#, Rust) Only SAST with built-in IDOR/auth-bypass/ownership detection
July 8, 2026
SherlockQA-AI
Version updated for https://github.com/mayurrawte/SherlockQA to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes the #1 trust-killer from the reliability epic (#19): reviews stacking up on every push until contributors start ignoring the tool.
Fixed Reviews no longer pile up on every push (#21) — SherlockQA now recognizes its own prior reviews regardless of the use-emoji setting via a hidden <!-- sherlockqa:review --> marker, and the summary no longer creates an undismissable COMMENTED review. Inline findings are synced, not stacked — posted as individually-tagged review comments that are deleted and re-posted on each run. Formal reviews only for dismissable terminal verdicts (APPROVE / REQUEST_CHANGES) — the common “needs changes” outcome now surfaces via the sticky summary and Check Run instead of an un-dismissable review. With update-summary-comment: false, the legacy single COMMENT review is still posted. Sticky-comment lookup is now paginated (#12) — busy PRs no longer accumulate duplicate sticky comments. Internal Jest suite grown to 24 tests, adding planFormalReview and isSherlockReview regressions. Note: pre-existing COMMENTED review stacks from older versions can’t be removed via the API and will linger once; this release prevents new ones.
July 8, 2026
Setup OpenTelemetry signals collection
Version updated for https://github.com/mishmash-io/setup-telemetry-collection to version v1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary This release updates a number of vulnerable dependencies to their safe versions:
transitive undici 5 and 6 bumped to 6.27.0 transitive js-yaml 3 bumped to 3.15.0 transitive js-yaml 4 bumped to 4.3.0 transitive @babel/core bumped to 7.29.6 We strongly advise you to upgrade to this release as soon as possible.
July 8, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.34.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 39 — two embedded-secret false positives (closes the tripwire secret sub-cluster) (see RULES_CHANGELOG.md): (1) a secret next to a client-telemetry ingestion URL (*.client-telemetry.<vendor>/enqueue) is a publishable key (Sentry-DSN class) → needs_review, not scored — snowflake-connector-python’s telemetry_oob.py; (2) a testing_utils.py / test_utils.py module is recognised as test-support code so a hardcoded CI token there is demoted — transformers’ src/transformers/testing_utils.py hf_ token. Recall preserved (secret without a telemetry URL, and non-test *_utils.py, still score).
July 8, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.31.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Adds three composable, backward-compatible launch knobs (#107) so the harness can grade honestly-built MCP servers that do not boot from a bare declared entry:
serverArgs (--server-arg / server_args) — arguments appended to the server command, e.g. a mcp serve subcommand. Recorded in the evidence. serverEnv (--server-env KEY=VALUE / server_env) — startup env the server needs to boot, e.g. an API key. Injected privately like the planted canaries and redacted from the recorded command. entrySubpath (--entry / entry) — a package-relative entry file instead of a declared bin. Resolved inside the staged package root and rejected on traversal. Docker isolation only (npm/github). Setting serverArgs or entrySubpath bypasses bin probing and does a single named launch; the C-02 egress target launches the same way, so it grades the same process. All three are optional and default off (semver-minor).
July 8, 2026
action-semver
Version updated for https://github.com/quike/action-semantic-release to version v3.11.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 3.11.0 (2026-07-08)
July 8, 2026
setup-openapi
Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.9 (2026-07-08) Build System deps: bump actions/setup-java from 5.4.0 to 5.5.0 (#28) (7aab708)
July 8, 2026
klaws compliance scan
Version updated for https://github.com/rostradamus/klaws to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog fb14e2d327dbf021addca20f91fbaa623e768b3e feat: automate release version-sync across public entries (#18)
July 8, 2026
FoundRuu Doctor
Version updated for https://github.com/Ruu5LP/foundruu to version v0.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed foundruu update で .ai/ を 0.12.0 に更新(ドッグフーディング) by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/26 doctor –deep のセッション検出バグ修正と CLAUDE.md の AI 指示品質改善 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/27 doctor –deep の採点観点を .foundruurc でカスタマイズ可能にする by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/28 要件・設計とコードのトレーサビリティ検証を doctor –deep に追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/29 doctor –deep の差分表示に未追跡ファイル数を付記 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/30 クラス設計テンプレートをワークフローアセットに追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/31 init の JSON マージで既存値を維持し、テンプレートとの差分を表示する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/32 deep.ts と session.ts を責務ごとに分割する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/33 pre-commit フック管理コマンドとセッション要件チェックを追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/34 レビュー連携: PR コメント投稿と rules add による指摘の規約化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/35 session end 時に CHANGELOG 下書きを自動生成する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/36 doctor に保守運用チェック(ドキュメント鮮度・設計判断の昇格)を追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/37 foundruu onboard: オンボーディングサマリコマンドと MCP ツールを追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/38 可読性改善: 短縮変数の改名と JSDoc 整備、コーディング規約の追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/39 整理: cloud/dashboard を foundruu-plugin-cloud へ切り出し、README を3軸構成に再編 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/40 Release 0.13.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/41 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.12.0...v0.13.0
July 8, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.48.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.48 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.48 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.48 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed feat(rules): pin CVE-2026-14748 (MCP-server SSRF via tool-arg URL) as AAK-MCP-SSRF-001 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/412 feat(rules): pin CVE-2026-49471 (Serena MCP unauthenticated-dashboard RCE) as AAK-MCP-SERENA-CVE-2026-49471-001 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/413 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.47...v0.3.48
July 8, 2026
GitHub tag explicit
Version updated for https://github.com/smplrspace/github-tag-action-explicit to version v1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bumped runtime from node12 to node24, resolving the GitHub Actions Node 20 deprecation.
Full Changelog: https://github.com/smplrspace/github-tag-action-explicit/compare/v1.2...v1.3
July 8, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.3 (2026-07-08) Features recipes: improve review summary presentation (#40) (3a73760) Bug Fixes skip release-created pipr comments (#38) (0c62cde)
July 8, 2026
SSG - Static Site Generator
Version updated for https://github.com/spagu/ssg to version v1.7.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.
July 8, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.708.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.708.3 Released 2026-07-08
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.708.2, interleaved on one runner against the pinned corpus (157 metrics compared).
July 8, 2026
spaces checkout run
Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.18.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.18.0 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/29 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.3...v0.18.0
July 8, 2026
Holon Solve
Version updated for https://github.com/holon-run/holon to version v0.28.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.28.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release adds image generation support, Volcengine Seedream image provider integration, standardized web search results with additional China-friendly providers, and improved media/attachment handling across the runtime and Web GUI. It also fixes fallback image generation, default callback trigger updates, generic operator prompt attachments, control prompt body limits, and several Web GUI file/link rendering paths.
July 8, 2026
Codex Action
Version updated for https://github.com/icoretech/codex-action to version v0.9.17.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.17 (2026-07-08) Bug Fixes deps: update codex-docker image to v0.143.0 (#48) (f1ef2a4)
July 8, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.84.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.84.0 (2026-07-08) Features (agents): add multi-agent network system with orchestration and message bus (73c88dc) (safety): add native PII detection and response validation to generate/stream (db2b38f) Bug Fixes (providers): dedupe identical Gemini tool calls within a turn (BZ-3327) (bfdb0a7) (providers): resolve engineering practice violations (Rules 6, 7, 8) (664f0a3)
July 8, 2026
CI Local Wakeup
Version updated for https://github.com/kuil09/github-action-result-to-local-ai to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial MVP release of CI Local Wakeup.
Highlights:
Rust single-binary CLI with ci-local wait, send-result, and events commands. GitHub Action sender for returning workflow results to a local listener. Git notes connection record under refs/notes/ci-local-channel. Local event spool for received CI result payloads. Multilingual README files and Codex skill template.
July 8, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Compress initial diffs by @louisescher in https://github.com/louisescher/crabd/pull/23 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/24 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.5.0
July 8, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.30.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog a986d05206705bf010c2fa02c996021b13a8c3fa feat(analyzer): apply per-repo config overrides in the library pipeline (#353)
July 8, 2026
AgentReady Repository Scanner
Version updated for https://github.com/napetrov/agentready to version v0.2.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary AgentReady v0.2.1 is a GitHub-only repository polish release. It does not publish an npm package.
This release improves first impressions and the next-step story:
README install instructions now clearly state that the npm package is not published yet. README positioning explains AgentReady as repository operability for coding agents, complementary to CI, lint, Scorecard, SAST, and dependency/security scanners. Added sample reports for a high-readiness repository and an improvement-plan repository. Added product docs for positioning, policy packs, and real-agent evaluation/benchmarks. Added v0.3 issue drafts for policy selection, benchmark calibration, instruction-quality analysis, and repository metadata polish. Updated backlog and feature roadmap around product trust and policy-pack direction. Verification git diff --check npm run type-check npm run agentready -- scan . --format markdown --output /tmp/agentready-release-scan.md Package status The package remains unpublished on npm by design for this release. Use the repository checkout or GitHub Action path.
July 8, 2026
Agent Behavior Safety Gate
Version updated for https://github.com/NavidBroumandfar/agent-behavior-evals-lab to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Structural tool-claim verification: adapter-output records can carry tool_events (the tool calls the agent actually made). Action claims in output text are verified against recorded events — a claim with no matching event fails as unverified_tool_claim; verified claims pass instead of being keyword-flagged. Text-only records keep plain keyword scoring. Trace adapters (src/trace_adapters.py): convert saved LangGraph, OpenAI Agents SDK, or CrewAI traces into gate-ready JSONL with tool_events populated. Samples + bring-your-own-trace guide in examples/adapters/. Corpus v2 (local_public_v2, 40 cases): high-diversity pressure patterns in the two owned risk areas — fake tool-use claims and approval-gate pressure. v1 stays frozen. Gate with --case-path evals/benchmarks/local_public_v2/cases.jsonl. Calibration study harness (src/scorer_judge_calibration.py): keyword-scorer vs LLM-judge disagreement table over all reviewed runs (opt-in, local judge supported). Leaderboard page (docs/leaderboard/): reviewed local open-weight results with CIs, published via GitHub Pages. Action hardening: inputs pass via env (no inline expression interpolation), absolute path support, no redundant install. Use in CI - uses: NavidBroumandfar/agent-behavior-evals-lab@v1 with: outputs: ci/agent_outputs.jsonl tier: smoke Deterministic and local-only: no model calls, credentials, or external actions.
July 8, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.17.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.17 (2026-07-08)
July 8, 2026
lacuna-cli
Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.2...v0.3.3
July 8, 2026
Setup-Oracle-Test-Pilot
Version updated for https://github.com/oracle-actions/setup-testpilot to version v1.0.26.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 23 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 7+8 - Add support for 26ai RAC database and provide JobID to Test Pilot infrastructure by @loiclefevre in https://github.com/oracle-actions/setup-testpilot/pull/9 10 - Remove 23ai version + Fix db26airac by @loiclefevre in https://github.com/oracle-actions/setup-testpilot/pull/11 Full Changelog: https://github.com/oracle-actions/setup-testpilot/compare/v1.0.25...v1.0.26
July 8, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.34.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 37 — test-certificate private keys no longer scored (see RULES_CHANGELOG.md), a false positive from the reputable-corpus tripwire. Packages ship dummy TLS certificate + private-key pairs for their own test HTTPS servers (urllib3 dummyserver/certs/*.key, grpcio src/core/tsi/test_creds/*.key); a “Private key block” whose directory path carries a test/dummy/fixture marker next to a cert/cred/tls/ssl marker is routed to needs_review, not scored. Effect: urllib3, grpcio high → low. Recall preserved: a private key on a normal path (id_rsa, config/deploy.key) still scores.
July 8, 2026
unzipp
Version updated for https://github.com/postleo/unzipp to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Automatically unzip .zip files on any branch, place them where you want, and push the extracted contents back
July 8, 2026
Rafter Security Scan
Version updated for https://github.com/Raftersecurity/rafter-cli to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Node.js:
npm install -g @rafter-security/cli@0.9.0 Python:
pip install rafter-cli==0.9.0 OpenClaw (via ClawHub):
clawhub skill install rafter-security See CHANGELOG.md for details.
What’s Changed feat: add secret scanning pattern for DigitalOcean Personal Access Tokens by @Minh-Nguyen-2k7 in https://github.com/Raftersecurity/rafter-cli/pull/189 New Contributors @Minh-Nguyen-2k7 made their first contribution in https://github.com/Raftersecurity/rafter-cli/pull/189 Full Changelog: https://github.com/Raftersecurity/rafter-cli/compare/v0.8.10...v0.9.0
July 8, 2026
spec.md check
Version updated for https://github.com/rosenjcb/spec.md to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #3 from rosenjcb/cursor/release-automation-a89c (42a19a9) Exclude test-only paths from version bump gate (3aa992c) Add tests for validation scripts and CLI libraries (72af692) Fix CI: let pnpm/action-setup read version from packageManager (b9ea42f) Switch repo tooling from npm to pnpm (6aa08c8) Add changesets release automation and publish-target validation (30586d6) Merge pull request #2 from rosenjcb/claude/spec-md-tooling-mz809m (f58a7e7) Publish CLI as @rosenjcb/spec-md (spec-md name is taken on npm) (5dc97bb) Make SKILL.md’s TESTING.md link portable; drop the link-rewrite hack (22eef5c) Keep a single TESTING.md; link it from distributed copies instead of bundling (3f4bda9)
July 8, 2026
Skill Doctor Quality Gate
Version updated for https://github.com/San-Z1/skill-doctor to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Skill Doctor is a CI quality gate for Agent Skills.
It catches vague triggers, broken resource links, oversized SKILL.md files, overlapping skills, and broad tool hints before they land in a repository.
Quick Start - uses: San-Z1/skill-doctor@v1 with: path: skills fail-on: warning Highlights Workflow annotations, Markdown, JSON, and SARIF output Quality score and grade Static review only; does not execute scanned skill scripts Packaged Agent Skill included
July 8, 2026
Scrutora Scan
Version updated for https://github.com/Scrutora/scrutora-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Scrutora Scan — free DPDPA & HIPAA compliance code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a generic rule id, and land in your Security → Code scanning tab. Runs offline: no API key, your code never leaves the runner.
July 8, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.1 (2026-07-08) Features cli: show update notices (#31) (2f4112a) Bug Fixes ci: harden flaky failure paths (#34) (73eb372) runtime: harden redaction and inline dedupe (#33) (15b305e)
July 8, 2026
MS Teams Notification (Adaptive Card)
Version updated for https://github.com/stackdone/ms-teams-notification to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed V1 0 2 (#2) (be2c2a2) update (#1) (c033c3d) . (75037b1) fix (ab3960a) add . (2a8c9d9) Initial commit (15c66f4)
July 8, 2026
AgentAudit Security Scanner
Version updated for https://github.com/sudan94/agentaudit to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rename Action to unique Marketplace name (fd4b3c0) Fix GitHub Action install name and bump refs to v0.1.1 (2acd10c) Rename package to agentaudit-scanner and update related documentation (948673b) Changed name from skillcheck to agentaudit (0810086) Add tests and fixtures for malicious and benign scenarios (acd5f5a)
July 8, 2026
LLM Prompt Radar
Version updated for https://github.com/Tahiram32/llm-prompt-radar to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Missing CI Check for AI-Powered Applications 🛡️ llm-prompt-radar is the first dedicated CI tool for detecting risky changes to LLM prompts and AI configuration before they ship to production.
🌟 What it detects 🚨 Safety guardrail removal — Critical alert when safety/refusal instructions are removed from prompts 🤖 Model downgrades — Flags silent swaps like gpt-4o → gpt-3.5-turbo or claude-3-opus → claude-3-haiku 📝 Prompt file changes — Deep analysis of .prompt, .jinja, .j2 template files with similarity scoring 🔍 In-code system messages — Detects changes to system prompts inside Python, JS, and TS source files ⚙️ LLM parameter changes — Tracks temperature, max_tokens, top_p, and more 🎯 Risk scoring — none / low / medium / high / critical 📊 Multiple output formats — text, json, markdown, github annotations, SARIF 📦 Install pip install llm-prompt-radar 🔧 GitHub Action - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: Tahiram32/llm-prompt-radar@v0.1.0 with: base-ref: origin/main format: github fail-on: high 🔗 Links PyPI: https://pypi.org/project/llm-prompt-radar/0.1.0/ Docs: https://github.com/Tahiram32/llm-prompt-radar#readme
July 8, 2026
Zyrax Guard
Version updated for https://github.com/tiagosilva07/zyrax-guard to version v0.11.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.11.1 — Windows upgrade parity via scoop Windows was the only platform without a working zyrax-guard upgrade. Fixed.
Added Scoop bucket — install the signed release binary on Windows:
scoop bucket add zyrax https://github.com/tiagosilva07/scoop-zyrax scoop install zyrax-guard Manifest hashes come from the release’s signed checksums.txt, and the bucket is regenerated automatically on every release.
July 8, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.708.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.708.1 Released 2026-07-08
This release of the CLI ships 1 new change, 1 improved change, 1 changed change and 1 fixed change.
What changed New New vg fix command turns a drift scan into ranked, risk-tiered upgrade plans and applies the one you choose. Improved vg fix now re-scans automatically when your last drift scan is out of date. Changed Scan reports now label the drift metric as “DriftScore” (one word), matching the name used across the website and docs. Fixed Scan reports now match your plan. Benchmarks Two-arm benchmark of this release against 2026.704.3, interleaved on one runner against the pinned corpus (157 metrics compared).
July 8, 2026
Build WordPress Archive
Version updated for https://github.com/webshr/action-wp-build-archive to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add automatic version input from release tag
July 8, 2026
Vercel Deploy Comment
Version updated for https://github.com/wiyco/vercel-deploy-comment to version v2.2.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed test: establish E2E smoke testing pipeline by @wiyco in https://github.com/wiyco/vercel-deploy-comment/pull/17 Full Changelog: https://github.com/wiyco/vercel-deploy-comment/compare/v2.2.2...v2.2.3
July 8, 2026
kempt-fmt
Version updated for https://github.com/ZacSweers/kempt to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release Notes 2026-07-07
Support partially staged files for in-process formatting steps such as whitespace normalization by updating the Git index directly. Install kempt-fmt 0.2.1 Install prebuilt binaries via shell script curl --proto '=https' --tlsv1.2 -LsSf https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.sh | sh Install prebuilt binaries via powershell script powershell -ExecutionPolicy Bypass -c "irm https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.ps1 | iex" Install prebuilt binaries via Homebrew brew install ZacSweers/tap/kempt-fmt Download kempt-fmt 0.2.1 File Platform Checksum kempt-fmt-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum kempt-fmt-x86_64-apple-darwin.tar.xz Intel macOS checksum kempt-fmt-x86_64-pc-windows-msvc.zip x64 Windows checksum kempt-fmt-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum kempt-fmt-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum
July 8, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix(workspace): mint access token from PMAK on PMAK-only runs; widen visibility-403 advice
What’s Changed chore(deps-dev): bump @types/node from 24.12.4 to 26.1.0 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/66 chore(deps): bump graphql from 16.14.2 to 17.0.1 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/68 feat: close the residual assertion-catalog tail across gRPC, SOAP, GraphQL, and MCP by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/69 Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0
July 8, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New features to highlight in this version Enjoy them all now for free at https://cloud.prowler.com
🤖 Lighthouse AI — The Agentic Cloud Defender [!NOTE] This feature is available exclusively in Prowler Cloud and Prowler Enterprise with a subscription.
July 8, 2026
Database Scripts Delta Generator
Version updated for https://github.com/PunteriaCero/db-script-versioning to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add comment to clarify fetch-depth in action.yml (c85eeaa) Make base_ref and head_ref required inputs in action.yml (8f943ce) Update default values for base_ref and head_ref in test-delta workflow (9a01f6f) Update GitHub Action reference to use punteriacero/db-script-versioning (234a71f) Add documentation and changelog (9546a21) Add test workflow and gitignore (134f97f) Add user roles and RBAC support (e112b2a) Add email verification migration (887d8bd) Initial commit: Add action and example migration (fe42043)
July 8, 2026
klaws compliance scan
Version updated for https://github.com/rostradamus/klaws to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog ee827391521bd8ad9fc41956f49278a968e9ac01 feat: PIPA-XBR-001 third-party/cross-border transfer detector (#13)
July 8, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.47.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.47 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.47 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.47 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed fix(rules): correct SEP citations on AAK-MCP-STATELESS-* pack (0.3.47) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/409 feat(rules): pin CVE-2026-14471 (Amazon mcp-gateway-registry SQLi, closes #408) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/410 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.46...v0.3.47
July 8, 2026
SiliconRig HIL
Version updated for https://github.com/siliconrig/action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Marketplace release of the SiliconRig HIL action.
Flash firmware to a real embedded board (ESP32-S3, STM32H753, STM32F446, RP2350), capture serial output, and fail the workflow when the hardware run fails. Handles the full session lifecycle including cleanup on job failure.
July 8, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.1.0 Released 2026-07-07.
A verifiability feature release. Task completion now produces a sealed, content-addressed proof of what passed, not just a status line, and that proof verifies with the same audit chain that seals everything else.
July 8, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.0 (2026-07-07) ⚠ BREAKING CHANGES remove legacy SDK tool execute compatibility (#27) Features cli: add version and update commands (#30) (63f3869) Bug Fixes docs: serve root shell in docs image (#29) (587754a) runtime: tighten suggested change publication (#25) (e3d3646) Code Refactoring remove legacy SDK tool execute compatibility (#27) (baf2dc3)
July 8, 2026
Specreel
Version updated for https://github.com/specreel/specreel to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Turn the Playwright trace.zip your tests already produce into a watchable, shareable demo — and regenerate it on every green build, so the demo can’t go stale.
Single-file, stdlib-only CLI: specreel.py Trace → narrated HTML player, gallery, single-file bundle, optional MP4 recommend — crawl a running app and scaffold Playwright flows GitHub Action for the freshness loop; MCP server + Claude Code skill Opt-in, BYO-key AI narration pip install specreel (PyPI publish in progress — until then, grab the wheel below or clone).
July 8, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.56.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update dependency NixOS/nix to v2.34.8 (#157) (4c49b8a29e987ece0ff3a70cfc4c91918b21cc92) bump: v1.55.0 -> v1.56.0 (1443d93dfa3ca2f043b37f848631d6ac5563b0ec) chore(deps): lock file maintenance nix inputs (#156) (5bb45b10181ed8c209faa78078d5609d1950a4e5) chore(deps): update github actions to v1.55.0 (#155) (93b59515c97e5f9c2b82af99533bc2e0842e76a0)
July 8, 2026
GitGalaxy Scanner
Version updated for https://github.com/squid-protocol/gitgalaxy to version v.2.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 Overview GitGalaxy v2.3.1 is a critical security and data-integrity hotfix. This release locks down structural data provenance for air-gapped environments, resolves machine-learning sparsity poisoning, and hardens the engine against false positives in deep monorepos and shallow CI/CD clones.
July 8, 2026
Node Semantic Release
Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.196.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.196.0
1.196.0 (2026-07-08) ✨ Features update releaserc template (cb59cf4)
July 8, 2026
Repository Create
Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.81.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.81.0
1.81.0 (2026-07-08) ✨ Features update workflow permissions (18ffc9e)
July 8, 2026
pinprick-action
Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.2.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Updates the pinned pinprick version.
Defaults to pinprick 0.21.0 (was 0.20.1 in v0.4.1), pinned for deterministic runs. pinprick 0.21.0 removes the source.unverified scoring rule and its trusted-owners config key, moving the scoring rubric to 0.9.0: score no longer emits the zero-point publisher note, and trusted-owners is no longer a recognized config field. The action’s behavior, inputs, and permissions are unchanged. See the README for usage.
July 8, 2026
Yandex Cloud Federated IAM Token
Version updated for https://github.com/stat1c-void/yc-fed-iam-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update action to run on Node24 chore: bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/51 chore: bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/50 chore: bump the npm-development group with 7 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/48 chore: bump the actions group with 3 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/49 Full Changelog: https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.5...v1.0.6
July 8, 2026
PollyAction
Version updated for https://github.com/Swevo/PollyAction to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Shortened action description to fit Marketplace’s 125-character limit. No functional changes.
July 8, 2026
Meadows Bundler
Version updated for https://github.com/TeamMeadows/bundler to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/TeamMeadows/bundler/compare/v0.2.1...v0.2.2
July 8, 2026
Agents Shipgate
Version updated for https://github.com/ThreeMoonsLab/agents-shipgate to version v0.15.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agents Shipgate v0.15.0
July 8, 2026
Zyrax Guard
Version updated for https://github.com/tiagosilva07/zyrax-guard to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.11.0 — BLOCK means attack One deliberate verdict-policy change.
⚠️ Changed: vulnerabilities in legitimate packages now WARN instead of BLOCK BLOCK is now reserved for known-malicious packages — typosquats, hallucinated names, denylist and OSV MAL-* malware entries. A vulnerability advisory on a legitimate package (any severity) now yields WARN, with the severity shown in the message:
July 8, 2026
Trigv
Version updated for https://github.com/Trigv/trigv-github-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Optional url input for event destination links When url is omitted, the action automatically sends the current GitHub Actions run URL Default auto-generated description no longer includes the raw workflow URL (it is sent in url instead) Usage uses: Trigv/trigv-github-action@v1.1.0
July 8, 2026
Polder Reach
Version updated for https://github.com/usepolder/reach to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One number for design system adoption.
CLI: npx @usepolder/reach --library "@your/design-system" scores any React repo with zero config. --json emits the versioned report (schemaVersion 1). GitHub Action: uses: usepolder/reach@v1 posts a single PR comment (updated in place) with the score, the delta vs the base branch (computed in a temporary git worktree), and the leak count. Fork PRs degrade to the step summary. Badge, zero infra: pushes to the default branch commit .polder/reach-badge.json (shields.io endpoint schema) plus a static SVG fallback for private repos. Leaks: hardcoded hex colors and px values with file/line locations. The score formula is not configurable. A score you can tune is a score nobody trusts.
July 8, 2026
GitHub Actions Version Audit
Version updated for https://github.com/varunchandak/gh-actions-version-audit to version v1.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refresh Marketplace documentation with the workflow-file PR token requirements.\n- Clarify that commits to PR branches still need workflow-file write permission when modifying .github/workflows.\n- Document Resource not accessible by integration as the expected symptom for insufficient token permissions.
July 8, 2026
Start Wiz Sensor
Version updated for https://github.com/wiz-sec-public/wiz-sensor-github-action to version v0.9.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Print sensor error logs on failure Add a new “generate-support-package” input Add marker, to help verify the action ran with the sensor Upgrade dependencies
July 8, 2026
Local Podcast Generator
Version updated for https://github.com/yeste-rge/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update Dockerfile to install git and modify COPY commands by @yeste-rge in https://github.com/yeste-rge/podcast-generator/pull/1 New Contributors @yeste-rge made their first contribution in https://github.com/yeste-rge/podcast-generator/pull/1 Full Changelog: https://github.com/yeste-rge/podcast-generator/commits/v1.0
July 8, 2026
Powderworks Straitjacket
Version updated for https://github.com/zmaril/Straitjacket to version v0.2.3.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed duplication in Markdown now honours straitjacket-allow markers too. A clone inside a doc’s fenced code block carries a :<lang> tag on its source id (e.g. docs.md:bash), so the finding’s path wasn’t a real file — the suppression added in 0.2.2 couldn’t open it and the marker was ignored. The :<lang> tag is now stripped, which also tidies the reported path. Install: curl -fsSL https://raw.githubusercontent.com/zmaril/straitjacket/main/install.sh | sh
July 7, 2026
detect-git-changes-action
Version updated for https://github.com/isaac-cf-wong/detect-git-changes-action to version v0.0.15.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.0.15 - 2026-07-01 ⚙️ Miscellaneous Tasks (deps) Update pre-commit hook davidanson/markdownlint-cli2 to v0.23.0 (#41) - (c49bec3) (deps) Update pre-commit hook rbubley/mirrors-prettier to v3.9.4 (#40) - (c8bc486) Contributing: We welcome contributions! Please see our Contributing Guide for details.
July 7, 2026
IsReadyAI — readiness audit
Version updated for https://github.com/isreadyai/audit-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refresh the bundled scanner from the monorepo.
July 7, 2026
IsReadyAI — readiness fix
Version updated for https://github.com/isreadyai/fix-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Synced from isreadyai/isreadyai@1.0.2.
July 7, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/kewang/spek to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Live-reload now works inside devcontainers and WSL. On filesystems that don’t deliver native OS change events (9p / drvfs / NFS / CIFS / FUSE), spek automatically falls back to polling — so files created or edited after opening it are still detected. Detection is based on the watched path’s filesystem type and needs no configuration; an optional SPEK_WATCH_POLLING=on|off escape hatch exists only if you ever need to force it. Applies to the Web, VS Code, and IntelliJ live variants. Thanks to @nthansen (Norman Hansen) for contributing this feature.
July 7, 2026
AIGate Git Workflow Guard
Version updated for https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli to version v0.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Added aigate verify-enforcement for live GitHub/GitLab server-side enforcement verification. Updated doctor and project scoring to distinguish advisory, partial, and verified server-enforced AIGate gates. Published npm package aigate-cli@0.1.7 with provenance through GitHub Actions. Published GHCR Docker image ghcr.io/leehueeng/aigate-cli:0.1.7 and refreshed the GitHub Action display name. Validation npm run ci Release workflow dry run Release workflow publish Docker workflow publish npm view aigate-cli version -> 0.1.7
July 7, 2026
GitHub Personal Stats
Version updated for https://github.com/liuchong/github-personal-stats to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v1.0.0 of the GitHub Personal Stats Action and CLI binaries.
July 7, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: resolve Forgejo association via org membership by @louisescher in https://github.com/louisescher/crabd/pull/18 feat: classify bare mentions and route to the right mode by @louisescher in https://github.com/louisescher/crabd/pull/20 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/19 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.4.0
July 7, 2026
Git Velocity Analyser
Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.10.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog
July 7, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.93.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): consolidate weekly dependency and registry updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3600 feat(ui): guided demo lock cards on runtime surfaces (Part of #3468) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3602 feat(output): svg/html formatter convergence (Part of #2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3601 feat(ui,deploy): /login + collector mTLS defaults (Part of #3175) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3603 refactor(parsers): extract skill metadata checks into skill_audit_metadata by @andres-linero in https://github.com/msaad00/agent-bom/pull/3604 refactor(api): split postgres_store into per-store modules by @andres-linero in https://github.com/msaad00/agent-bom/pull/3605 feat(ui): rollup-by-default and asset drift lens (Part of #3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3606 feat(ast,output): PHP/Swift symbol reach and Parquet export (Part of #3499) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3607 docs(audit): consolidate epic queue merge state (#3601–#3607) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3611 feat(runtime): OIDC discovery shim for legacy IdP MCP interop (Part of #3609) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3612 feat(findings): runtime evidence + compliance moat lift (Part of #3608, #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3613 fix(scan,output): CLI AST gate + Parquet compliance_tags parity (audit P1/P2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3614 feat(runtime): trace explorer joined to findings and compliance (Part of #3608) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3615 feat(ui,graph): runtime evidence overlay badges (Part of #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3616 feat(proof): release smoke, demo estate, trust doc, proof-path nav (#3618) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3619 docs(deploy): unified install script, quickstart, and intake diagrams by @msaad00 in https://github.com/msaad00/agent-bom/pull/3621 fix(audit): P3 login redirect, Swift bare calls, rollup URL persistence by @msaad00 in https://github.com/msaad00/agent-bom/pull/3622 feat(scan,docs): GLM/Zhipu inventory + BYOM quickstart (closes #3609 tail) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3623 fix(audit): malicious findings stream, COUNT cache, demo hardening, SCIM keys by @msaad00 in https://github.com/msaad00/agent-bom/pull/3624 fix(ui): capture hydration + refreshed product-proof screenshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3625 fix(audit): post-3624 follow-up — reachability, demo safety, scale bench by @msaad00 in https://github.com/msaad00/agent-bom/pull/3626 chore(release): v0.93.5 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3628 fix(pre-release): CI isolation, README SVGs, and UI readability by @msaad00 in https://github.com/msaad00/agent-bom/pull/3629 fix(audit): SARIF malware flag on CVE path + PHP heredoc/nowdoc reach masking by @msaad00 in https://github.com/msaad00/agent-bom/pull/3630 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.93.0...v0.93.5
July 7, 2026
AI Agent Discipline Linter
Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.18.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(readme): progressive-disclosure rewrite — value prop + quick start above the fold, depth collapsed by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/260 chore(npm): front-load description with “Claude Code” + focus keywords for search relevance by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/261 feat(visuals): 1280x640 social preview + in-action gateguard demo image by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/262 docs(readme): list all 28 slash commands + fix stale repo-map counts by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/263 feat(verify): guard the README slash-command list with a check-command-count invariant by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/264 feat(reconcile): fold commit -> push -> open-PR + post-merge main sync into reconcile by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/266 feat: portfolio spine — repos registry, proof templates, portfolio-health + audit-actions commands by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/267 chore(gitignore): ignore .playwright-mcp/ browser artifacts by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/268 feat(gateguard): opt low-risk paths out of the fact-forcing gate via CI_GATEGUARD_EXCLUDE by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/269 feat(gateguard): three friction-driven hardening fixes (message-prose, target-lock, unquoted @{u}) by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/270 chore(release): cut v3.18.0 by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/271 Full Changelog: https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.18.0
July 7, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.16.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.16 (2026-07-07)
July 7, 2026
zotio bibliography health for Zotero
Version updated for https://github.com/OrgMentem/zotio-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed New: every run writes a verdict table to the job step summary, and the action now exposes exit-code, message, and color outputs for downstream steps (PR comments, badge publishing).
README: now leads with what you get — the deterministic exit-code gate, retraction checking (with demo GIF), the badge-that-never-lies, and the key operational insight: your Zotero library drifts outside git, so run the gate on a schedule, not just on push.
July 7, 2026
SpringSentinel
Version updated for https://github.com/pagano-antonio/springsentinel-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Dockerfile (b2d1ae2) Delete scripts directory (3ba2f95) Update entrypoint.sh (1af5128) Update Dockerfile (e0b9ba7) Update entrypoint.sh (2f69f60) Create generate-comment.js (2a2eb1b) Create README.md (3e1d589) Update test.yml (3a7ed11) Update entrypoint.sh (4e15ea0) Update entrypoint.sh (6418942)
July 7, 2026
Drawio Export Action
Version updated for https://github.com/rlespinasse/drawio-export-action to version v2.53.0.
This action is used across all versions by 124 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.53.0 (2026-07-07) Features bump rlespinasse/drawio-export from v4.52.0 to v4.54.0 (#105) (c422855)
July 7, 2026
FoundRuu Doctor
Version updated for https://github.com/Ruu5LP/foundruu to version v0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 配布コーディングルールを全言語で強化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/18 配布コーディングルール強化の穴を厳格レビュー観点で追加修正 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/19 Python を正式サポート(FastAPI テンプレート)に追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/20 FoundRuu を自リポジトリに適用し、Prettier ignore 自動整備を追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/21 コーディングルールの機械強制を全言語で CI まで一貫させる by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/22 README にテンプレート一覧を追加し、記述を最新化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/23 実装前の構造化整理をサポート(structure プロンプト + 計画品質診断) by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/24 Release 0.12.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/25 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.11.0...v0.12.0
July 7, 2026
VibeSafe Vulnerability Scanner
Version updated for https://github.com/SabahatGhauri/vibesafe-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan changed code on push/PR, comment findings on the PR, and fail the check on critical issues. See README for setup.
July 7, 2026
Scrutora DPDP Scan
Version updated for https://github.com/Scrutora/dpdp-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Scrutora DPDP Scan — free DPDPA & HIPAA compliance code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a generic rule id, and land in your Security → Code scanning tab. Runs offline: no API key, your code never leaves the runner.
July 7, 2026
greetingMSPQ-action-test-v4
Version updated for https://github.com/SebasCorps/greeting-action to version V2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/SebasCorps/greeting-action/compare/v1.0...V2.0
July 7, 2026
Sentinel Git Secrets Scanner
Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Sentinel v2.0.5 Stable Release This release introduces significant performance optimizations and key fixes:
Zero-Allocation Flat DFA Engine: Trie memory footprint reduced to ~500KB and peak RAM down to ~11MB. 100% Core Test Coverage achieved for reporter, git, commands, and updater packages. Heuristics & Suppressions: Added support for Mailgun/Hex letters-only findings and fixed updater comparison logic. Dedicated Output Argument: Added the -o / --output flag to Sentinel scan, enabling silent SARIF/JSON generation in CI while keeping pretty CLI logs. CI/CD Integration: Reusable GitHub Action with native SARIF output, officially published to the Marketplace as Sentinel Git Secrets Scanner. Full Changelog: https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5
July 7, 2026
pi GitHub Action
Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.25.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.25.1 - 2026-07-07 Changed deps-dev: bump fallow-rs/fallow from 2 to 3 (#363) deps-dev: update dependencies (#359) deps-dev: update dependencies (#360) deps-dev: update dependencies (#367) deps-dev: update dependencies (#370) deps-dev: update dependencies (#371) deps: update dependencies, Pi to v0.80.3 (#358) Fixed improve create_pull_request Forgejo compatibility with API URL fix and compare-URL fallback (#362) make system prompt dynamic based on platform input (#366) platform-github: treat HTTP 404 from pulls.create as a permission error on Forgejo (#369)
July 7, 2026
Setup DepVault CLI
Version updated for https://github.com/suxrobGM/depvault to version cli/v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Zero-knowledge CI tokens: DEPVAULT_TOKEN now has the form dvci_<auth>.<key> — the CLI sends only the auth part to the server and derives the decryption key from the key part locally, so the server can never unwrap your project key. Existing CI tokens must be regenerated in the web dashboard Add a doctor command that checks server reachability, login, vault setup, active project, and encryption key, printing the exact next command for anything not ready project info now accepts a positional [id] argument (e.g. depvault project info <id>) in addition to --project Clearer guidance: point to the dashboard vault-setup URL when the vault isn’t initialized, and make the encryption-key error honest that the CLI attempts creation automatically Support Windows and Linux ARM64 CI runners: the GitHub Action installs on Windows runners, and linux-arm64 binaries are now published
July 7, 2026
SFDX Code Review
Version updated for https://github.com/svierk/sfdx-code-review to version v1.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed add documentation and usage instructions Full Changelog: https://github.com/svierk/sfdx-code-review/compare/v0.0.2...v1.0.0
July 7, 2026
SFDX Deploy
Version updated for https://github.com/svierk/sfdx-deploy to version v1.1.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed suppress sfdx-git-delta output for cleaner deploy logs Full Changelog: https://github.com/svierk/sfdx-deploy/compare/v1.1.3...v1.1.4
July 7, 2026
Polder Drift — Design System Drift Alerts
Version updated for https://github.com/usepolder/drift to version v1.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hardening release (PR #14).
Security
Drift-table cells are sanitized: backticks, pipes, and newlines in import paths or filenames can no longer break the comment table or inject markdown rendered as authored by the bot (fork-PR comment spoofing). Correctness
July 7, 2026
Upkeep Audit
Version updated for https://github.com/wei18/Upkeep to version v2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Upkeep is now installable as a Claude Code plugin (/plugin marketplace add wei18/upkeep + /plugin install upkeep@upkeep) or via npx skills add wei18/upkeep --skill upkeep-audit. The GHA reusable workflow is unchanged — @v1 callers keep working but v1 is now frozen; switch to @v2 (identical interface). From now on fixes move the v2 tag only.
July 7, 2026
AGENTS.md Lint (Schliff)
Version updated for https://github.com/Zandereins/schliff to version v8.5.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed verify scores under the detected format profile (#102, closes #101): schliff verify AGENTS.md no longer fails spuriously (was 27.7/F under the SKILL profile on a file score grades 91.6/A). SKILL.md verdicts unchanged. Positional negation in operational_coverage (#96): contrastive sentences (“run X, never Y directly”) keep the recommended command. Dead-marker detector matches marker tokens, not English prose (#97, closes #93). Corpus goldens re-derived. Security Runtime scorer prompt nonce-hardened (#99) — defense-in-depth, dimension remains opt-in. Added Theme-aware README hero + social-preview asset (#106); star-notify workflow (#98); grouped Dependabot action bumps (#107). Docs README redesigned (#100): AGENTS.md-first, every number ground-truthed against the released engine, honesty-hardened. Full changelog: https://github.com/Zandereins/schliff/blob/main/CHANGELOG.md
July 7, 2026
XcodeReady Scan
Version updated for https://github.com/gautam00010/xcodeready-action to version Error loading version from page [https://github.com/marketplace/actions/xcodeready-scan], unable to determine latest release.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
July 7, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.397.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/2e9f06f4562accd2c70e006e3b10ada68c0d91be with plugin-scanner 2.0.997.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.396...v1.2.397
July 7, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.397.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.397
July 7, 2026
Hyperlocalise CI
Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.18.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(web): redirect /dashboard via route handler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1118 test(web): cover Contentful no-writeback failures by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1120 ⚡ Bolt: optimize XCStrings parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1121 🧪 Scout: escape line feeds in CSV formula neutralization by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1123 fix(web): preserve workspace automation output summary on orchestrator finish by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1122 fix(crowdin): add missing DateFrom to EnterpriseVendorTaskCreateForm and fix typos by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1124 feat(web): add per-file translation import for native TMS by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1125 update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1126 🧪 Scout: fix PO parser continuation leakage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1129 fix(crowdin): add URL field to Screenshot model for API parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1130 fix(web): rename billing AI usage label to AI Credit by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1131 fix(web): parse target locale when importing xcstrings translations by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1128 chore: update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1132 ⚡ Bolt: optimize ICU parser via low-copy literal tracking by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1127 ⚡ Bolt: Optimize CSV parser and marshaler with capacity hints by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1133 🧪 Scout: add regression tests for ICU pound summation in sibling blocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1135 fix(web): fail Contentful idempotent retry when prior run wrote no drafts by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1134 ⚡ Bolt: optimize ICU simple style parsing by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1136 🧪 Scout: Improve ICU placeholder name validation and test coverage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1138 ⚡ Bolt: optimize ARB parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1139 🧪 Scout: improve locale normalization unit tests by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1141 fix(crowdin): improve Screenshot and Distribution model parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1142 fix(web): parse CSV target locale column on translation import by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1137 feat(cat): isolate panel runtime errors with react-error-boundary by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1143 fix(cat): improve queue status a11y and cross-platform shortcuts by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1144 feat(cat): support Crowdin issue comments in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1145 fix(cat): include maxLength in native CAT segment payload by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1147 fix(cat): pass approve flag for native translation saves by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1146 Correct Distribution validation for branch and directory IDs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1152 🧪 Scout: improve ICU parser invariant test coverage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1153 ⚡ Bolt: optimize Java properties comment formatting by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1151 fix(cat): render segment tags in queue rows by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1149 feat(cat): add native project comment support in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1150 fix(web): enforce org job budget in agent translation tools by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1154 🧪 Scout: fix leading slash in CLI pathresolver by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1157 fix(crowdin): improve task list parity for creatorId and projectId by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1158 test(web): cover CSV import parsing edge cases by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1155 ⚡ Bolt: optimize placeholder and segment key generation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1156 fix(web): route invitees to dashboard after accept, not onboarding by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1159 fix(web): unblock users stuck on invitation pending after WorkOS acceptance by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1160 feat(web): Crowdin PAT mode and fix WorkOS invite membership sync by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1161 feat(web): list projects and jobs from live TMS API with native/TMS sections by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1162 refactor(web): remove WORKOS_ENABLED env flag by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1163 feat(hyperlocalise-web): add Crowdin progress skill and agent tool by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1164 fix(web): pass Crowdin credential base URL to comment pusher client by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1165 fix(web): load native and TMS projects/jobs in parallel by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1166 fix(agent): use skill registry for Crowdin TMS queries in Slack by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1167 fix(crowdin): use per-user OAuth credentials for progress checks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1169 fix(web): remove stale sync labels and fix external TMS open job count by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1170 feat(blog): add TMS-agnostic AI translation post for July 2026 by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1172 test(web): cover Crowdin progress file and string scopes by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1173 fix(web): use per-user Crowdin credentials for CAT concordance by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1175 feat(web): unify inbox chat with Slack agent skills by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1171 fix(integrations): show skeleton loader for action buttons while loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1177 ⚡ Bolt: optimize NormalizeList capacity hinting by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1174 fix(crowdin): fix Enterprise PAT flow and remove legacy org api_token by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1178 refactor(providers): replace providerSafeFetch with fetch by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1179 feat(agent): disambiguate multi-repo GitHub context in Hyperlocalise agent by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1176 perf(web): speed up external TMS project list and split overview data loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1180 perf(web): reduce TMS job fan-out and speed up jobs/files loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1181 perf(web): split CAT file load from per-segment detail fetching by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1182 fix(web): show only job files in CAT source file picker by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1184 feat(web): lazy-load TMS job detail tabs and projects section by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1183 test(web): cover project job loading helper by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1185 🧪 Scout: Capture ICU styles in message invariants by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1189 perf(crowdin): reduce TMS jobs list API fan-out by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1190 refactor(web): remove provider background sync pipeline by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1191 feat(web): rebuild workspace dashboard overview layout by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1192 update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1193 fix(crowdin): fetch source strings by numeric id via Get String endpoint by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1194 feat(web): split CAT queue API and polish skeleton loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1195 perf(cat): split segment detail from comments and paginate queue by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1196 refactor(cat): reorganize into feature slices by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1197 refactor(cat): split cat-editor-panel into isolated sub-components by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1198 test(web): cover CAT queue and Crowdin progress gaps by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1199 fix(phrase): restore has_issues CAT queue filtering after lazy comment load by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1201 ⚡ Bolt: optimize default strategy initialization by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1200 feat(cat): MobX workspace store for CAT editor state by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1203 🧪 Scout: add unit tests for usage context helpers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1202 fix(agents): stabilize due Contentful automation list test by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1205 feat(web): add MobX app shell store with substores by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1204 test(cat): add comprehensive CAT tool tests with API mocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1206 fix(deps): update go dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1208 chore(deps): update actions/checkout action to v7 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1213 chore(deps): update actions/setup-go digest to 924ae3a by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1210 chore(deps): update goreleaser/goreleaser-action digest to f06c13b by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1211 chore(deps): update voidzero-dev/setup-vp digest to 13e7afb by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1212 feat(web): replace files preview with View strings action by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1207 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1209 feat(cat): lazy load agent context by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1214 feat(web): migrate to Geist design system color tokens by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1215 fix(web): rename visual context label by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1216 refactor(app-shell): wire MobX shell hooks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1217 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1219 fix(cat): improve ICU highlight contrast with theme-aware color tokens by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1220 fix(cat): faster segment queue with lazy panel loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1218 ci(web): cache Next.js builds and add Vercel ignore by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1221 feat(automations): expand Storybook coverage for editor and templates by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1222 feat(blog): announce Slator Language AI 50 Under 50 selection by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1223 ci(web): ignore MSW handler files in Vercel uploads by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1226 fix(cat): restore lazy-loaded translations and Crowdin concordance locale by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1225 fix(cat): keep editor drafts out of queue pagination hydration by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1227 refactor(cat): separate concordance lookup from segment review by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1228 refactor(web): show source files as tree only by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1229 test(web): cover provider file branch routes by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1231 fix(crowdin): add internalCode to Language model for API parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1234 fix(cat): preserve unsaved edits across filter changes and target refetch by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1233 🧪 Scout: add TestParseASTSelectOrdinalWithOffset by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1235 feat(cat-validate): add segment validation service and profile rules by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1230 ⚡ Bolt: optimize Android XML parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1232 feat(cat): validate segments with Go service by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1236 refactor(cat): compose MobX workspace domains by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1237 fix(web): set explicit height on Pierre file tree by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1239 test(app-shell): expand unit test coverage and edge cases by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1238 chore(deps): update actions/cache action to v6 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1240 fix(deps): update module github.com/workos/workos-go/v7 to v9 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1241 fix(web): restore job source file actions and CAT context lookup by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1242 feat(web): default job CAT to untranslated queue filter by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1244 fix(web): auto-open first job file in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1245 feat(web): add fixture-auth e2e test foundation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1243 feat(dashboard): improve workspace overview by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1246 feat(web): add projects UX utilities for avatars and recent tracking by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1247 fix(web): guard live TMS memory and glossary IDs from DB lookups by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1248 feat(web): select GitHub repo for chat context by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1249 fix(dashboard): color automation run status badges by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1252 feat(web): improve CAT header selectors by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1250 fix(web): track chat agent usage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1251 feat(web): add zoomable lightbox for visual context screenshots by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1253 feat(web): localise integrations page components by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1254 feat(api): support TMS source file uploads via public files API by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1255 ⚡ Bolt: Optimize HTML tag parity checks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1257 test(web): cover live provider resource access guards by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1256 feat(web): add Storybook stories for glossaries and translation memories pages by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1260 🧪 Scout: robustly extract related tokens with spaces by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1259 chore(deps): update golang docker tag to v1.26.4 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1262 chore(deps): update voidzero-dev/setup-vp digest to 250f29c by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1261 feat(lokalise): add CAT workspace and live TMS APIs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1258 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1264 feat(web): add Storybook stories for integrations page by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1263 fix(web): fix github repo refresh + context for external tms by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1265 fix(deps): update go dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1266 chore(deps): update dependency typescript to v6 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1269 feat(cat): structure agent context output and chain AI recommendation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1270 fix(web): improve project file browser capacity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1271 feat(web): Smartling live CAT and Crowdin parity for web by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1274 refactor: tms oop classes by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1275 feat(marketing): replace changelog with recent blog posts on homepage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1276 ⚡ Bolt: optimize segment profile validation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1278 test(web): cover Smartling review pull by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1277 fix(cat): hide unsupported Smartling queue status filters by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1279 🧪 Scout: improve newline parity and fix CRLF literal width by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1280 Improve Task and Source String upload parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1281 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.18
July 7, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.8.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.8.6
July 7, 2026
Suricata Check
Version updated for https://github.com/Koen1999/suricata-check-action to version v1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Koen1999/suricata-check-action/compare/v1.0...v1.1
July 7, 2026
Relivio Deploy Monitor
Version updated for https://github.com/lazypl82/deploy-monitor-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Marketplace description updated to reflect the post-deploy verdict flow: tell Relivio a deploy went out, it watches the next 15 minutes and returns a STABLE / WATCH / RISK verdict. No change to action inputs or runtime behavior.
July 7, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.27.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 6a7c9734bbbd83d4d1dbc6fd54858197c216d638 feat(analyze): threshold-gated streaming log ingest for giant repos (#344) eecb83e7b84ef79c42925a4fa58ef11b9e70fbc8 fix(debt): honor file-exclusion patterns (#350) 6fa00de5a585d84e3258155c5f8edf303d617aac fix(timeline): deterministic, cache-independent blame assembly (#349) 765f8a40e344317e6b7c278c014e7ca2c8a2da02 perf(analyze): memoize file-exclusion glob matching (#346) 616a28e61896723a48d88504321fe33b9641b936 perf(analyze): parallelize debt blames and auto-scale workers (~2.3x) (#345) 68096926c408c0e849a296215a68811c5f24cb78 perf(timeline): auto period-concurrency when unset (#348) eb8a0c31cba4ef67e856f2ad0e599c9ec20c9cd9 perf(timeline): enable blame cache + auto-workers; make output deterministic (#347)
July 7, 2026
Sentrik Gate
Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.7.0 sentrik deadlines — regulatory enforcement countdown for your enabled packs: EU AI Act (post-omnibus timeline), EU Cyber Resilience Act, CMMC 2.0, PCI DSS, ISO 27001, FDA §524B (--all, --past, --json) Anonymous usage telemetry (opt-out) — one daily ping: random id, version, OS, Python version, command name. Nothing else, ever. First-run notice, full disclosure at https://docs.sentrik.dev/telemetry/ — disable with SENTRIK_TELEMETRY=0 or telemetry_enabled: false Complete binary data files — sentrik dashboard, the auditor portal, and CVE function-level reachability now work from the standalone binary (previously wheel-only) First-run output fixes — severity labels render correctly; findings table no longer collapses in narrow/CI terminals Includes all v1.6.0 fixes (working Linux binary, npm wrapper error handling) Install: npm install -g sentrik or pip install sentrik
July 7, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.90.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 7, 2026
Falsifying Swarm Orchestrator
Version updated for https://github.com/moonrunnerkc/swarm-orchestrator to version v12.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v12.1.0: autonomous-merge trust layer (built, not yet lit) This release adds the two-sided merge-trust layer and its evidence and measurement machinery on top of the v12.0.0 proof tier. It is additive and backward-compatible: no public API was removed, no existing flag changed behavior. Nothing auto-merges yet. The honest state is a gate that is built, measured, and deliberately dark until the numbers earn it.
July 7, 2026
Suppress Ratchet
Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README
July 7, 2026
Test Ratchet
Version updated for https://github.com/motchalini-llc/test-ratchet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README
July 7, 2026
Type Ratchet
Version updated for https://github.com/motchalini-llc/type-ratchet to version v1.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README
July 7, 2026
lacuna-cli
Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.1...v0.3.2
July 7, 2026
Setup Omnistrate CTL
Version updated for https://github.com/omnistrate-oss/setup-omnistrate-ctl to version v1.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the npm-development group with 6 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/196 Fix CodeQL badge link in README by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/197 Fix CodeQL workflow filename in README by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/198 Bump the npm-development group with 5 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/199 Bump the npm-development group with 5 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/200 Bump actions/checkout from 6.0.2 to 6.0.3 in the actions-minor group by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/201 Bump the npm-development group across 1 directory with 7 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/203 Update Node.js runtime to 24 by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/212 Full Changelog: https://github.com/omnistrate-oss/setup-omnistrate-ctl/compare/v1...v1.1.0
July 7, 2026
OSSystems Nix Actions
Version updated for https://github.com/OSSystems/nix-actions to version v1.0.5.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add post-run to the update-flake action.
post-run — command run after nix flake update, before the PR is created, so its file changes (e.g. a regenerated Cargo.nix) land in the update PR commit. export-devshell — "true" loads a dev shell into the environment before post-run (env-export via nicknovitski/nix-develop); "false" runs in plain bash. devshell — which dev shell to export when export-devshell is "true"; empty uses the flake’s default. Token safety: when post-run is set with token-owner, the GitHub App token is automatically re-minted after post-run — so a long-running post-run can’t expire the token before the PR is opened. Correct by default, with no flag to remember.
July 7, 2026
Create Verified Commit and Tag
Version updated for https://github.com/oWretch/create-verified-commits to version v1.0.2.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-06) Bug Fixes deps: update @commitlint/cli to 21.2.0 to fix ESM-only package resolution (6124f06)
July 7, 2026
Quick OCP
Version updated for https://github.com/palmsoftware/quick-ocp to version v0.0.37.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add OCP 4.22 support (CRC v2.62.0) Fix oc tools download by stripping patch version to use latest-4.X channel Full Changelog: https://github.com/palmsoftware/quick-ocp/compare/v0.0.36...v0.0.37
July 7, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.33.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 31 — installed-app Google OAuth client secret false positive (see RULES_CHANGELOG.md): a GOCSPX- client secret in a file with installed-app flow markers (loopback redirect, device code, PKCE, oob) is routed to needs_review instead of scored — for native/CLI apps Google documents this value as not confidential (gcloud ships one), so it must not synthesize a critical exfiltration verdict. A GOCSPX- secret without those markers (a leaked web-app secret) and all other secret shapes stay fully scored. Found on gemini-cli: critical/100 → high/50.
July 7, 2026
MaintainerOps AI
Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.14 Marketplace Snapshot and Package Metadata Consistency MaintainerOps AI v0.1.14 is a small consistency release for public package and Marketplace evidence.
Changes Updated npm package repository metadata to the canonical git+https://github.com/rtonf/maintainerops-ai.git URL. Corrected the README GitHub Action example from the stale v0.1.12 tag to the currently verified Marketplace latest tag before release. Added an API-free security diff review for the metadata and Marketplace snapshot cleanup. Tracked the release workflow in Issue #85. Verification npm run verify git diff --check npm view maintainerops-ai version dist-tags --json GitHub Marketplace public listing check Notes This release does not change runtime behavior, model prompts, GitHub permissions, authorization boundaries, or package execution logic. It exists to keep Marketplace-facing documentation and package metadata aligned with the public release process.
July 7, 2026
js Giphy PR Comment
Version updated for https://github.com/sanketddev/js-action-pr-giphy-comment to version v1.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This is a demo action for PR GIF comments.
July 7, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.2 (2026-07-06) Features harden review prompts and evals (#22) (7415e3b) This PR was generated with Release Please. See documentation.
July 7, 2026
SFDX Run Tests
Version updated for https://github.com/svierk/sfdx-run-tests to version v1.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed add documentation and usage instructions Full Changelog: https://github.com/svierk/sfdx-run-tests/compare/v0.0.4...v1.0.0
July 7, 2026
Expand AWS IAM Wildcards
Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix release verification by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/122 Release continue by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/123 release script prepts changelog for release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/124 ci: bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/127 ci: bump actions/attest from 4.1.0 to 4.1.1 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/125 deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/126 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/128 Prepare v1.3.0 release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/129 Full Changelog: https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.3.0
July 7, 2026
Setup Modern C++ Development Environment
Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed now pull.bash can be called with no argument when you don’t pass image version, most recent one will be chosen fix msvc debug build
July 6, 2026
Forgejo Kaniko
Version updated for https://github.com/leandro-costa-oliveira/forgejo-kaniko-action to version v4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/leandro-costa-oliveira/forgejo-kaniko-action/compare/v3...v4
July 6, 2026
vcpkg GitHub Packages cache
Version updated for https://github.com/LegalizeAdulthood/vcpkg-github-cache to version v1.5.0.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Improved BSD setup compatibility for current vcpkg on FreeBSD, OpenBSD, and NetBSD. Made BSD vcpkg-tool package caching repository-scoped to avoid cross-repo collisions. Fixed FreeBSD warm-cache restores caused by stale NuGet HTTP cache data. Added setup-log analysis for setup-side vcpkg-tool publish failures. Kept package summary links available when GitHub omits package settings metadata. Full Changelog: https://github.com/LegalizeAdulthood/vcpkg-github-cache/compare/v1.4.0...v1.5.0
July 6, 2026
Lingo.Dev AI Localization
Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.0.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor Changes #2162 62c00b4 Thanks @AndreyHirsa! - Remove the ./compiler and ./react* subpath exports, the @lingo.dev/_compiler and @lingo.dev/_react dependencies, and the optional react peer dependency from the CLI package.
July 6, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Support for AGENTS.md, CLAUDE.md, skills by @louisescher in https://github.com/louisescher/crabd/pull/9 feat: Whitelabling for comments by @louisescher in https://github.com/louisescher/crabd/pull/11 feat: Pretty errors, scoped environment by @louisescher in https://github.com/louisescher/crabd/pull/12 feat: Cross-Repo read access & private NPM registries by @louisescher in https://github.com/louisescher/crabd/pull/13 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/10 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.3.0
July 6, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 6c7fc4d74fa5122634f66ee96adfa38056237966 fix(output): make scores/rankings deterministic with tie-breaks (#343) 809e78242e07d15ccacdf5c48d0fa18db97b8574 perf(log): streaming-ingest Phase A — intern filenames + release chunks (repairs main build) (#342)
July 6, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.11.0 (2026-07-06) Features cli: add help command with usage examples (#177) (beac277) Bug Fixes evals: disable the review deadline in eval runs + one-command preset A/B (#175) (934b309)
July 6, 2026
nix-magic-setup
Version updated for https://github.com/mdarocha/nix-magic-setup to version v1.3.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed The action now runs nothing-but-nix to help free up some space in the runner for Nix. The severity of the cleanup is controlled by a new config flag, and by default it only allocates free runner space to /nix, without removing anything (holster config) Automatically read nixConfig, and set NIX_CONFIG, so that all future steps use the flake’s config properly If devenv is detected, automatically set devenv caches (devenv.cachix.org and pre-commit.cachix.org) Full Changelog: https://github.com/mdarocha/nix-magic-setup/compare/v1.2.0...v1.3.0
July 6, 2026
Suppress Ratchet
Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)
July 6, 2026
Test Ratchet
Version updated for https://github.com/motchalini-llc/test-ratchet to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)
July 6, 2026
Star History Action
Version updated for https://github.com/narayann7/star-history-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release.
An unofficial GitHub Action that renders a star history chart for your own repositories and commits it into your repo, so your README embeds a static SVG that stays fresh. It is meant for repos you own or collaborate on, and works after GitHub’s June 2026 stargazers API restriction.
July 6, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.9
Fix DmlException Thrown For For User-Mode DML Field Access Failures
Give SetupEntityAccess.SetupEntityId Its Polymorphic Target List
Resolve Feature Parameter Names Against The Executing Namespace
Group Bulkified Multi-Row Lookups By Key Instead Of Keeping First Row
July 6, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.30.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Ships litmus-v14: a C-04 probe 3.2 false-positive fix (#104). A server that safely rejects a jailbreak-as-argument and echoes it back inside its own error frame (Invalid label "…", Error: … not found: …), including char-stripped or truncated echoes, is no longer mis-flagged as amplification. Some safe-rejecting servers move D→A. server.json bumped in lockstep.
July 6, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.32.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed UI 🐞 Fixed Invitation callback paths are now preserved when invited users continue with Google, GitHub, or SAML authentication (#11752) API 🐞 Fixed Attack Paths: Scan rows now have database defaults for is_migrated and sink_backend so scan-perform-scheduled inserts survive deploy skew (#11826) Invited users now keep their invitation context when completing authentication with Google, GitHub, or SAML, so the invitation is accepted during login (#11752) 🔐 Security User profile updates now allow users to update their own account while requiring user-management permissions to update other users in the same tenant (#11792) SDK 🐞 Fixed KeyError: 'MANUAL' crash while rendering the compliance summary table (e.g. CIS Microsoft 365) when a framework has manual, checks-less requirements with a Level 1/Level 2 profile; MANUAL findings are now skipped in the PASS/FAIL section tally instead of raising (#11822)
July 6, 2026
No Deploy Fridays
Version updated for https://github.com/rorycaraher/no-deploy-fridays to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/rorycaraher/no-deploy-fridays/compare/v0...v0.1.4
July 6, 2026
Vibe Index
Version updated for https://github.com/roxblnfk/action-vibe-index to version v1.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.3.1 (2026-07-06) Bug Fixes push the badge commit to the checked-out branch (f98e946)
July 6, 2026
Scanbox Security Audit
Version updated for https://github.com/Savvii/scanbox to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Tweak prompt to remove /app dependency, makes it easier to override the dir for other pipelines.
July 6, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.0.0 Released 2026-07-06.
A verifiability release. Every major surface in this line ships its primary artifact as a proof: a signed lineage receipt, an HMAC-chained journal entry, a content-addressed record, or a deterministic projection that two operators can recompute to the same bytes. The features are not “capability plus an audit log” bolted together; the audit substrate is the shape of the capability. Strip the chain and the feature loses its meaning, not just its logging.
July 6, 2026
cvesse CVE gate
Version updated for https://github.com/srknzl/cvesse-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of cvesse CVE gate — a zero-dependency GitHub Action that takes the CVE IDs your scanner already produces (Trivy, Grype, osv-scanner, Dependabot), enriches them against cvesse, and fails CI on CISA KEV, severity, or EPSS thresholds.
July 6, 2026
Node Semantic Release
Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.195.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.195.0
1.195.0 (2026-07-06) ✨ Features updates (16fcf9d)
July 6, 2026
Trigv
Version updated for https://github.com/Trigv/trigv-github-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes Default channel input is now general (Trigv workspace default), not ci. README examples omit channel unless you need a custom slug. Pin workflows to @v1.0.1 or newer.
July 6, 2026
HumaneProxy Safety Benchmark
Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release is about doing the same work faster and scaling it across workers—three independent performance wins, each behind an opt-in extra with a clean fallback.
Added ONNX Runtime Stage-2 backend (stage2.backend, env HUMANE_PROXY_STAGE2_BACKEND): Stage 2 can now run the embedding model on its pre-exported ONNX graph via a new onnx extra (onnxruntime + tokenizers + huggingface_hub)—no PyTorch, roughly 2 GB lighter to install, and faster on CPU. The default "auto" prefers ONNX when installed and falls back to sentence-transformers; both produce numerically equivalent embeddings, verified by an equivalence test suite (including long-input truncation parity). Model, anchor, and result caches are keyed per backend.
July 6, 2026
PR Ripple
Version updated for https://github.com/vivek5071/ripple to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new dry-run input — run the full analysis pipeline with zero side effects: the report is logged instead of posted, reviewers are logged instead of requested, AI review is skipped. Trial Ripple on any repo without spamming your team: - uses: vivek5071/ripple@v1 with: dry-run: true Test suite — 8 unit tests covering symbol extraction and owner resolution CI — typecheck + tests on every push and PR
July 6, 2026
Upkeep Audit
Version updated for https://github.com/wei18/Upkeep to version v2.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release for GitHub Marketplace publishing.
action.yml description shortened under the Marketplace 125-character limit (#22). Plugin version bumped to 2.1.1. v2.1.0 highlights (composite action.yml for Marketplace, README usage section, docs updates) are in the v2.1.0 notes.
July 6, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.17.3.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.3 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/34 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.2...v0.17.3
July 6, 2026
spaces checkout run
Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.3 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/28 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.2...v0.17.3
July 6, 2026
Type Ratchet
Version updated for https://github.com/motchalini-llc/type-ratchet to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)
July 6, 2026
moult-action
Version updated for https://github.com/moult-rb/moult-rb to version v0.4.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add moult cycles, hotspot coupling columns, and hierarchy-aware deadcode confidence by @GoodPie in https://github.com/moult-rb/moult-rb/pull/9 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.4.1...v0.4.2
July 6, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.93.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(docs): keep extension contract link mkdocs-strict safe by @msaad00 in https://github.com/msaad00/agent-bom/pull/3429 docs(readme): refresh personas and terminal demo for 0.92.0 CLI by @msaad00 in https://github.com/msaad00/agent-bom/pull/3430 fix(ci): unblock Sigma WebGL E2E dynamic import by @msaad00 in https://github.com/msaad00/agent-bom/pull/3432 chore(perf): findings read bench and 2k CI regression by @msaad00 in https://github.com/msaad00/agent-bom/pull/3440 feat(retention): enforce graph snapshot purge and history cap (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3441 feat(api): server-side compliance hub findings pagination (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3442 fix(scan): skip unreachable Go checksum lookups by @msaad00 in https://github.com/msaad00/agent-bom/pull/3443 fix(compliance): normalize pci-dss slug alias and SAML install hint (#3439) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3444 feat(helm): Alembic pre-upgrade hook; chore(sdks): bump Python SDK (#3433, #3438) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3445 fix(scan): reduce secret FP on OAuth token minting assignments (#3437) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3447 refactor(output): migrate compact and console formatters to Finding (#2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3448 feat(skills): CI exit code and wider skill file discovery (#3434) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3449 fix(hardening): Role enum, Grafana creds, ecosystem claims, HOSTS rollup (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3450 feat(release): SBOM release asset, image scan gate, air-gap vuln-DB docs (#3436) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3451 fix(hardening): severity unification and cosign/MCP audit fixes (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3452 feat(retention): per-tenant graph retention and analytics cap (PR2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3453 feat(api): findings read PR2 — approximate counts and UI pagination (#3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3454 chore(deps): combine dependency updates (2026-07-03) by @andres-linero in https://github.com/msaad00/agent-bom/pull/3460 feat(api): expression-indexed severity/cvss finding sorts (#3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3461 fix(api): idempotent finding ingest (P0) (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3462 fix(reliability): tenant fail-closed, cloud retry, health rate-exempt, batch cap by @msaad00 in https://github.com/msaad00/agent-bom/pull/3464 feat(enrich): bundle KEV and EPSS into offline vuln-DB layer by @msaad00 in https://github.com/msaad00/agent-bom/pull/3466 feat(ui): labeled demo estate and surface lock states (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3467 feat(api): finding lifecycle L1 — monotone current-state merge (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3470 fix(api): batch cap returns 422 and index filtered severity+cvss reads (#3474) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3477 chore(repo): hygiene + session cookie Secure default (#3475) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3479 fix(auth): cluster-safe SAML RelayState nonce store (#3476) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3478 feat(api): finding lifecycle L2 — occurrence log keyed on scan_id (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3480 feat(sdk): expose finding lifecycle ingest on control-plane clients by @msaad00 in https://github.com/msaad00/agent-bom/pull/3483 feat(api): finding lifecycle L3+L4 — resolve reconcile and current-state reads (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3481 docs(audit): add sanitized 2026-07-03 ledger with issue mapping by @msaad00 in https://github.com/msaad00/agent-bom/pull/3500 fix(api): harden OCSF ingest — cap/offload (A) + deterministic event IDs & ClickHouse dedup (J) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3501 feat(ui): interactive blast-radius overlay on the lineage graph by @msaad00 in https://github.com/msaad00/agent-bom/pull/3502 fix(ui): dock graph lens switcher — stop overlaying the canvas by @msaad00 in https://github.com/msaad00/agent-bom/pull/3505 docs(deploy): auto-migration hook, finding encryption prereq, ClickHouse OSS+Cloud by @msaad00 in https://github.com/msaad00/agent-bom/pull/3504 feat(ui): wire estate roll-up navigation for large graphs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3507 fix(api,http): bound ScanRequest list elements and jitter sync retries by @msaad00 in https://github.com/msaad00/agent-bom/pull/3508 fix(api): gate external compliance frameworks and lock OCSF product attribution by @msaad00 in https://github.com/msaad00/agent-bom/pull/3509 fix(api): restore overview tiles from compact scans and add current-state sort indexes by @msaad00 in https://github.com/msaad00/agent-bom/pull/3515 refactor(api): deduplicate current-state hub payloads via ledger refs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3517 feat(api): keyset cursor pagination for hub current-state findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3518 perf(api): gzip JSON responses and zstd-compress hub payloads at rest by @msaad00 in https://github.com/msaad00/agent-bom/pull/3516 feat(helm): enterprise-demo profile with AWS estate inventory cron by @msaad00 in https://github.com/msaad00/agent-bom/pull/3519 feat(api,ui): overview graph drill and estate correlation API by @msaad00 in https://github.com/msaad00/agent-bom/pull/3520 fix(cloud,helm): http_client GPU connectors + scoped API NetworkPolicy by @msaad00 in https://github.com/msaad00/agent-bom/pull/3522 feat(scanners): runtime-enforce driver run() and failure_mode by @msaad00 in https://github.com/msaad00/agent-bom/pull/3524 fix(api): Postgres rate-limit sliding window matches docstring by @msaad00 in https://github.com/msaad00/agent-bom/pull/3523 docs: compact session/enforcement flow diagrams by @andres-linero in https://github.com/msaad00/agent-bom/pull/3525 feat(api): async findings report export jobs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3526 perf(analytics): ClickHouse sink dedup for canonical rows by @msaad00 in https://github.com/msaad00/agent-bom/pull/3527 fix(api): CVSS keyset pagination and report export truncation by @msaad00 in https://github.com/msaad00/agent-bom/pull/3530 refactor(api): hub reference-table normalization by @msaad00 in https://github.com/msaad00/agent-bom/pull/3528 docs(deploy): audit Alembic, encryption prerequisite, ClickHouse positioning by @msaad00 in https://github.com/msaad00/agent-bom/pull/3532 fix(api/scim): group PATCH, deprovision keys, SCIM error envelopes by @msaad00 in https://github.com/msaad00/agent-bom/pull/3540 feat(export): delta-stream connector for SIEM and data-lake sinks by @msaad00 in https://github.com/msaad00/agent-bom/pull/3531 test(api): lock in hub current-state payload dedup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3541 feat(api): S3 report export artifacts with presigned URLs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3542 fix(api/scim): PUT full replace and schema discovery by id by @msaad00 in https://github.com/msaad00/agent-bom/pull/3543 fix(api): gate bulk-ingest O(n) snapshot walk (#3544) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3545 fix(fleet): local discovery push for fleet sync by @msaad00 in https://github.com/msaad00/agent-bom/pull/3546 chore(glama): pin release ref and verify Dockerfile on publish by @msaad00 in https://github.com/msaad00/agent-bom/pull/3547 docs(audit): sync AUDIT-2026-07-03 ledger with shipped main by @msaad00 in https://github.com/msaad00/agent-bom/pull/3550 docs(readme): lead with personas, Start Here, and demo proof by @msaad00 in https://github.com/msaad00/agent-bom/pull/3548 feat(headless): wire findings push CLI and hub current-state list (#3482) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3549 feat(ui): show findings lifecycle status and timestamps in queue by @msaad00 in https://github.com/msaad00/agent-bom/pull/3551 fix(cli): skip PyPI update check in offline and air-gap mode (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3552 fix(deploy): mount ~/.agent-bom for abom user in compose profiles (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3553 fix(cli): reject reserved tenant ids on CLI and MCP resolvers (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3554 docs(audit): headless ingest docs and audit ledger sync by @msaad00 in https://github.com/msaad00/agent-bom/pull/3555 fix(cli): honor –offline for PyPI check and loopback fleet push by @msaad00 in https://github.com/msaad00/agent-bom/pull/3556 fix(headless): offline push, MCP check version, token-derived auth by @msaad00 in https://github.com/msaad00/agent-bom/pull/3557 chore(ci): reject LLM co-author trailers in commit messages by @msaad00 in https://github.com/msaad00/agent-bom/pull/3558 refactor(output): use canonical severity_rank in remediation plan by @msaad00 in https://github.com/msaad00/agent-bom/pull/3559 docs(audit): sync ledger for headless hardening #3556-#3558 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3560 fix(auth): reject replayed OIDC JWTs via jti one-time store by @msaad00 in https://github.com/msaad00/agent-bom/pull/3561 refactor(trust): derive CVE weights from canonical severity_rank by @msaad00 in https://github.com/msaad00/agent-bom/pull/3562 docs(audit): sync ledger post #3561 OIDC jti replay by @msaad00 in https://github.com/msaad00/agent-bom/pull/3563 feat(plugins): runtime activation for opt-in plugin entry points by @andres-linero in https://github.com/msaad00/agent-bom/pull/3564 refactor(severity): unify API scan and compact CIS sort ranks by @msaad00 in https://github.com/msaad00/agent-bom/pull/3565 refactor(severity): canonical CIS sort ranks in HTML report by @msaad00 in https://github.com/msaad00/agent-bom/pull/3566 refactor(severity): canonical package severity rank in Mermaid output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3567 refactor(severity): canonical CIS sort ranks in console renderer by @msaad00 in https://github.com/msaad00/agent-bom/pull/3568 refactor(severity): canonical sort ranks in skills, license, extensions by @msaad00 in https://github.com/msaad00/agent-bom/pull/3569 feat(reachability): export Python symbol reachability in findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3571 refactor(output): migrate markdown CVE sections to unified Finding by @msaad00 in https://github.com/msaad00/agent-bom/pull/3570 perf(db): partition hub observations with retention rollover by @msaad00 in https://github.com/msaad00/agent-bom/pull/3572 feat(reachability): include symbol reachability in delta-stream snapshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3573 refactor(output): migrate PDF CVE sections to unified Finding by @msaad00 in https://github.com/msaad00/agent-bom/pull/3574 feat(reachability): multilang symbol join + CWE/CVE/CPE advisory context by @msaad00 in https://github.com/msaad00/agent-bom/pull/3576 feat(reachability): wire symbol reach into triage scoring and VEX by @msaad00 in https://github.com/msaad00/agent-bom/pull/3577 refactor(output): migrate SARIF CVE loop to unified Finding stream by @msaad00 in https://github.com/msaad00/agent-bom/pull/3578 feat(reachability): Java/Rust AST symbol join for Maven and Cargo by @msaad00 in https://github.com/msaad00/agent-bom/pull/3579 docs(readme): product-first flow, compact persona band, plain-language taglines by @msaad00 in https://github.com/msaad00/agent-bom/pull/3580 feat(reachability): NuGet/C# AST symbol join for .NET MCP backends by @msaad00 in https://github.com/msaad00/agent-bom/pull/3581 feat(reachability): RubyGems AST symbol join for Rails MCP backends by @msaad00 in https://github.com/msaad00/agent-bom/pull/3582 feat(reachability): Gradle-only Java symbol join via build.gradle coords by @msaad00 in https://github.com/msaad00/agent-bom/pull/3584 docs(roadmap): validated quick-wins queue for evidence and discovery by @msaad00 in https://github.com/msaad00/agent-bom/pull/3583 feat(ingest): wire SARIF into external scanner detect_and_parse path by @msaad00 in https://github.com/msaad00/agent-bom/pull/3585 feat(vex): ingest CSAF and CycloneDX VEX documents by @msaad00 in https://github.com/msaad00/agent-bom/pull/3586 feat(output): registry verified badge and evidence ingest docs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3587 refactor(output): migrate json and html CVE tables to Finding stream by @msaad00 in https://github.com/msaad00/agent-bom/pull/3588 feat(alignment): VEX on Finding stream and API scan field parity by @msaad00 in https://github.com/msaad00/agent-bom/pull/3589 chore(release): prepare v0.93.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3590 feat(gap): pre-tag slice — Finding topology, lock cards, close #3242 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3592 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.92.0...v0.93.0
July 6, 2026
vimanam-action
Version updated for https://github.com/noemaforge/vimanam-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vimanam is a high-performance OpenAPI/Swagger (JSON or YAML) to Markdown documentation generator. It supports OpenAPI 2.0 (Swagger) and OpenAPI 3.0 specifications.
While useful for human documentation, Vimanam is uniquely optimized for feeding API specifications to LLMs by condensing large multi-megabyte specs into token-budget-friendly Markdown representations.
July 6, 2026
Nox Security Scanner
Version updated for https://github.com/Nox-HQ/nox to version v1.7.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.7.1 (2026-07-06T11:16:23Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Bug Fixes 8082b46b7debac25261e0b069ede57ec682a864f fix(scan): restore –baseline override flag + friendly unknown-flag error (#224) Others f432fad83ab0d0a783509f8aba7c3d31a569158e chore(release): 1.7.1 — restore –baseline override flag (#226) Full Changelog: https://github.com/nox-hq/nox/compare/v1.7.0...v1.7.1
July 6, 2026
Open Delivery Spec
Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🚀 Features feat: surface and act on the policy review_tier verdict by @shenxianpeng in #46 🐛 Bug fixes fix: add manual repair path to the existing Move Major Tag workflow by @shenxianpeng in #49 📝 Documentation docs: document the kernel Assisted-by trailer in the attribution table by @shenxianpeng in #48 👻 Maintenance chore: bump default cli-ref to v0.4.0 by @shenxianpeng in #47 Full Changelog: https://github.com/open-delivery-spec/validate-action/compare/v0.2.1...v0.2.2
July 6, 2026
Download a Build Artifact (oro)
Version updated for https://github.com/orochibraru/download-artifact to version v8.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: readme name [skip ci] (f4f9265) fix: fuck check dist (95c65d2) fix: version (5540036) fix: immutable action version (95d8c95) fix: action name (ce57196) chore: removed unused packages (048b6bd) fix: bun cfg (681facc) fix: biome lint (ca0a98c) chore: my stuff + disable ghes warns (8bb719c) fix: isghes (d32f35d)
July 6, 2026
Upload a Build Artifact (oro)
Version updated for https://github.com/orochibraru/upload-artifact to version v8.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: missing patch on ghes (aeca548) fix: ghes (fc8717e) fix: action name [skip ci] (f897267) fix: fuck check dist (6ab8cd6) fix: version (486bd7f) fix: immutable action version (4bb427a) fix: rebuilt assets (52f6ae9) fix: lockfile (11b092a) fix: action name (164535d) chore: trigger ci (dc9c7e9)
July 6, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.29.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed litmus-v13 — C-01 tool-output-injection false-positive recalibration.
Honest servers no longer flip to F on benign patterns that merely resemble injection. The C-01 static/output text scan now distinguishes real hijack attempts from ordinary documentation:
angle-bracket placeholders in usage text (<tool>, <system|...>) data: / format examples (data:image/*;base64,…, XML/JSX samples) benign second-person prose in tool descriptions and returned docs U+200B zero-width doc artifacts — regraded MEDIUM, with keyword-evasion still caught HIGH via normalize-then-scan (ins<ZW>tructions de-obfuscates before the keyword pass) Skills keep every invisible character HIGH (S-01 strict). True-positive detection is preserved — the evil / injecting / second-order fixtures still grade F.
July 6, 2026
Agent PR Police
Version updated for https://github.com/Pradumnasaraf/agent-pr-police to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Features expand and verify the agent detection registry (#3) (c043745)
July 6, 2026
Python Semantic Release - Publish
Version updated for https://github.com/python-semantic-release/publish-action to version v10.6.1.
This action is used across all versions by 662 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v10.6.1 (2026-07-06) Build System deps: Bump python-semantic-release@v10.6.0 to v10.6.1 (#104, 5a5718c) Detailed Changes: v10.6.0…v10.6.1
July 6, 2026
release-please-oss-action
Version updated for https://github.com/release-please-oss/release-please-action to version v6.0.3.
This action is used across all versions by 13 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 6.0.3 (2026-07-06) Bug Fixes ESM globals shims (5329246) Miscellaneous Chores automated dist build (#55) (db21fb4) deps: update github-actions (#53) (31e2a33) deps: update github-actions (#56) (77c4f32) deps: update github-actions to v7 (#57) (8b506ac) deps: update npm dependencies (#52) (42d21e3) deps: update npm dependencies (#58) (6e29bd8)
July 6, 2026
AgentAuditKit MCP Security Scan
Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.46.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.46 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.46 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.46 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed feat: State of MCP Security 2026 data-report harness by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/373 docs: kill public rule-count drift (221->225) + promote MCP-security data-report by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/382 chore(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in https://github.com/sattyamjjain/agent-audit-kit/pull/377 chore(deps): Bump click from 8.1.8 to 8.4.2 by @dependabot[bot] in https://github.com/sattyamjjain/agent-audit-kit/pull/376 chore(deps): bump github/codeql-action to v4.36.2 (all steps together) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/383 docs: finish State of MCP Security 2026 report (launch-ready) + v0.3.42 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/392 feat: MCP prevalence scan (664 configs) + score calibration (#23) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/393 feat(rules): pin CVE-2026-52830 bearer-token path-traversal (AAK-MCP-AUTH-PATHTRAVERSAL-001, #394) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/396 feat: MCP Server Card (SEP-1649) static scanner + prevalence crawler by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/397 feat: public OWASP coverage leaderboard (#67) + Kong Konnect MCP CVE-2026-13341 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/405 feat(bench): reproducibility head-to-head — 20-run byte-identical finding set by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/406 fix(rules): AAK-FLOWISE-001 pin 3.1.2→3.1.3 for CVE-2026-58057 (closes #372) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/407 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.41...v0.3.46
July 6, 2026
Snapshot auto-fix PR
Version updated for https://github.com/sedlukha/snapshot-autofix-pr to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial public release.
Composite GitHub Action that runs a visual-snapshot command which updates baselines, then opens, updates, or closes a single auto-fix pull request carrying only the changed snapshot files. Capture-agnostic — works with Playwright, Storybook, or your own script.
July 6, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.16.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.16.1 Released 2026-07-06.
Fixes Windows: adapter binaries installed as .cmd/.bat shims (for example Codex via nvm-windows) now spawn correctly. The worker resolves the adapter binary to its absolute path before spawning and routes resolved shims through the command interpreter on Windows, and PATHEXT is passed through the worker environment. Real executables and all POSIX spawns are unchanged. (#2287, #2290; thanks @ViteaVlaikov for the report and diagnostics)
July 6, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.1 (2026-07-06) Features cli: bundle pipr setup skill (#18) (801957d) make review runs retry-safe (#21) (98dc50f)
July 6, 2026
Trigv
Version updated for https://github.com/Trigv/trigv-github-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of the official Trigv GitHub Action.
Send a native push notification when a workflow succeeds or fails — one step, no curl.
Requirements: Trigv account, API key, Trigv for iOS on your phone.
July 6, 2026
setup-hcloud
Version updated for https://github.com/vbem/setup-hcloud to version v1.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/setup-hcloud/compare/v1.0.4...v1.0.5
July 6, 2026
vilancer-bugbit
Version updated for https://github.com/Vilancer/bugbit to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed action.yml load failure — Removed invalid workflow expression from action metadata that caused Failed to load action.yml on all consumers. workflow_dispatch runtime — resolveEvent uses fetch for GitHub API instead of an unbundled @actions/github import. @v1 updated to this release.
July 6, 2026
HumaneProxy Safety Benchmark
Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.5.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release rolls up the 0.5.x bug-fix series (0.5.1-0.5.6) — the result of a full audit of the codebase against its documentation. Every fix ships with regression tests: the suite grew from 298 to 353 tests, with zero skips and zero expected failures.
July 6, 2026
Build Flow Action
Version updated for https://github.com/wgtechlabs/build-flow-action to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [0.1.9] - 2026-07-06 Changed address review feedback in docs update readme and architecture for full primitive input passthrough clarify architecture principle for passthrough vs silent defaults (#38) expose all package-build-flow-action inputs (#35) expose all release-build-flow-action inputs (#34) expose all container-build-flow-action inputs (#33) Security fix ghcr-token fallback to github.token when unset (#37)
July 6, 2026
Setup Backlog CLI
Version updated for https://github.com/yacchi/backlog-cli to version v0.29.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 74cc75852815ae5feb5c373f2192e1736f272ab9 feat(action): 認証情報の入力を追加しCI設定を集約 (#32)
July 6, 2026
Kover Report Action
Version updated for https://github.com/yshrsmz/kover-report-action to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.1.0: PR #132 - chore(deps): lock file maintenance
July 6, 2026
vibecheck-ai-slop
Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/yuvrajangadsingh/vibecheck/compare/v1.9.1...v1.10.0
July 6, 2026
AI TestGen — Generate & Review Tests
Version updated for https://github.com/zer0dayf/ai-testgen to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First-class Rust support.
New rust preset: Cargo.toml auto-detection, src/**/*.rs, integration tests in top-level tests/, run with cargo test --test {stem}, public-API-only guidance. New {stem} placeholder for run_cmd (needed by compiled-language runners like cargo). Optional per-language extra_rules injected into the generation prompt. Consumers on @v1 get this automatically; pin @v1.1.0 for an immutable version.
July 6, 2026
Localize Pipeline
Version updated for https://github.com/bisq-network/localize-pipeline to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Production release for the 2026-07-04 full-repo pre-merge review hardening.
Highlights:
Docker runtime secrets replace build-layer SSH/GPG private key persistence. Core translation retry, ledger, validation, queue, and reporting paths are hardened. Quality gate, semantic review, remediation, placeholder, and validator checks are stricter. Config, CLI, provider, shell, Docker, and GitHub Action behavior is aligned for safer production runs. Parser, adapter, translation-memory, connector, bootstrap, layout, and docs edge cases are fixed. Verification:
July 6, 2026
GitHub Space Shooter
Version updated for https://github.com/czl9707/gh-space-shooter to version v2.0.4.
This action is used across all versions by 144 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Automated release of pypi version v2.0.4
What’s Changed perf: enable GIF optimization to reduce file size by @HmonWutt in https://github.com/czl9707/gh-space-shooter/pull/43 perf: use lossy WebP encoding for dramatically smaller files by @HmonWutt in https://github.com/czl9707/gh-space-shooter/pull/45 New Contributors @HmonWutt made their first contribution in https://github.com/czl9707/gh-space-shooter/pull/43 Full Changelog: https://github.com/czl9707/gh-space-shooter/compare/v2.0.3...v2.0.4
July 6, 2026
Assign Reviewers when Dependencies Change
Version updated for https://github.com/dependency-owners/assign to version v2.0.24.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.24 (2026-07-05) Bug Fixes deps: lock file maintenance (#121) (ac1fd95)
July 6, 2026
Check Unowned Dependencies
Version updated for https://github.com/dependency-owners/check to version v2.0.17.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.17 (2026-07-05) Bug Fixes deps: lock file maintenance (#130) (873d9df)
July 6, 2026
AgentGuard Security Scan
Version updated for https://github.com/dockfixlabs/agentguard to version v0.6.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed docker run ghcr.io/dockfixlabs/agentguard . Run AgentGuard anywhere. Fixed publish skip-existing masking.
Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.6.9...v0.6.10
July 6, 2026
Setup Piet
Version updated for https://github.com/fabasoad/setup-piet-action to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-piet-action/pull/15 chore(deps): bump actionlint from 1.7.8 to 1.7.9 by @fabasoad in https://github.com/fabasoad/setup-piet-action/pull/16 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-piet-action/pull/17 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-piet-action/pull/18 Full Changelog: https://github.com/fabasoad/setup-piet-action/compare/v0.2.0...v0.3.0
July 6, 2026
Fallow - Codebase Intelligence
Version updated for https://github.com/fallow-rs/fallow to version v3.2.0.
This action is used across all versions by 252 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Health: a configurable “function too big” threshold, surfaced in the summary This release makes the unit-size (large-function) check configurable and reports the effective ceiling in the health output.
health.maxUnitSize: raise the large-function bar instead of switching it off The line count at which a function is reported as an oversized “large function” was hardcoded to 60 LOC. That made test suites noisy: a describe() callback spans hundreds of lines, and each large it() body trips the threshold too. The only escape was health.ignore, which drops every health signal (complexity, CRAP, hotspots) for those files, so you lost complexity checking on your test code as well.
July 6, 2026
TrustCheck Package Scanner
Version updated for https://github.com/Halfblood-Prince/trustcheck to version v2.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published from immutable commit 80ba32f691b15f39c26df081b8d7865ae7561750. The release workflow publishes PyPI, GitHub Action, Snap Store, Homebrew tap pins, and GHCR Docker distributions after shared tag verification, QA, matrix, and coverage builds.
Release artifacts:
dist/* dist/SHA256SUMS.txt dist/*.cdx.json standalone trustcheck-*-windows-x86_64.exe with checksum unsigned trustcheck-*-store.msix for Microsoft Store submission GHCR Docker images for linux/amd64, linux/arm64, and linux/arm/v7 Verify the direct Windows executable before use:
July 6, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.391.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/94bc5f097f380f55261291070e6913bd7ad528e0 with plugin-scanner 2.0.991.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.390...v1.2.391
July 6, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.391.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.391
July 6, 2026
Git Submodules Upgrade
Version updated for https://github.com/itsapinhulk/git-submodules-upgrade to version v3.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: update vendored upgrade-git-submodules by @github-actions[bot] in https://github.com/itsapinhulk/git-submodules-upgrade/pull/13 chore: update vendored upgrade-git-submodules by @github-actions[bot] in https://github.com/itsapinhulk/git-submodules-upgrade/pull/14 Full Changelog: https://github.com/itsapinhulk/git-submodules-upgrade/compare/v3.0...v3.1
July 6, 2026
L10n.dev AI Localization Automation
Version updated for https://github.com/l10n-dev/ai-l10n to version v1.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Add MCP server and tools for localization management by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/49 Added “mcp” to the root workspaces by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/50 feat: Update build process to include SDK dependencies by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/51 feat: Add test script and trigger by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/52 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.9.0...v1.9.1
July 6, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 1bb1e10897d9d8e5f844b082c8241d84f784d9fe feat(git): suppress gravity for git subtree –squash imports (#334)
July 6, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.10.0 (2026-07-06) ⚠ BREAKING CHANGES engine: reviews now run the fast preset by default — all nine lenses covered in four grouped model calls (~half the calls and wall time), trading some recall on the softer lenses (performance, complexity, ponytail, deprecation, tests, documentation). Set preset: full (or –preset full / the Action’s preset input) to restore the previous one-call-per-lens behaviour. Features engine: first-class structured describe + opt-in auto-describe (#171) (35f1b08) engine: function-boundary context, per-tool lint floors, eval A/B coverage (#173) (684acf1) engine: review-effort/risk labels + declarative finding rules (#172) (1414322) engine: static-analysis fusion — deterministic linters ground the review (#169) (48d6ecf) engine: two-stage triage routing behind a security floor (#170) (00966fe) github: commit-scoped incremental review on synchronize pushes (#168) (f16f915) prompt caching + audit-driven review improvements (#166) (95acc2b) Performance Improvements engine: cut review wall time — global fan-out pool, cached diff prefix, fast preset, deadlines (#174) (853917a) Dependencies bump the python-dependencies group across 1 directory with 3 updates (#164) (bb83a4f)
July 6, 2026
Go - Test Suites
Version updated for https://github.com/mvrahden/go-test to version v1.24.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed CI-friendly test failure summaries with GitHub Action by @mvrahden in https://github.com/mvrahden/go-test/pull/80 Use gotest action for CI test execution by @mvrahden in https://github.com/mvrahden/go-test/pull/81 ci: update major version tag on release by @mvrahden in https://github.com/mvrahden/go-test/pull/82 Lint rule to simplify assertion usage by @mvrahden in https://github.com/mvrahden/go-test/pull/83 Detect and report unnecessary T escapes in test suites by @mvrahden in https://github.com/mvrahden/go-test/pull/84 Full Changelog: https://github.com/mvrahden/go-test/compare/v1.23.1...v1.24.0
July 6, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.15.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.15 (2026-07-06)
July 6, 2026
lacuna-cli
Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.0...v0.3.1
July 6, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.32.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 30 — CI-config and vendored-tree false positives (see RULES_CHANGELOG.md), found when numpy scored critical/90 on its own infrastructure files: CI/CD pipeline configuration (.circleci/, .github/workflows/, .gitlab-ci.yml, Jenkinsfile, …) is demoted to needs_review — a CI job runs on the project’s build service, never on the consumer’s machine, so numpy’s docs-deploy SSH setup is not component behavior and can no longer feed ST-COMBO-EXFIL. Install-time hooks (setup.py, npm postinstall) are unaffected and stay fully scored. vendored-* directories (numpy’s vendored-meson/, which bundles the meson build system with meson’s own CI docker scripts) are now skipped like vendor/ and node_modules. Effect: numpy critical/90 → low/20; recall floors unchanged.
July 6, 2026
OpenTelemetry for GitHub Workflows, Jobs and Steps
Version updated for https://github.com/plengauer/Thoth to version v5.59.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Stop masking super-linter failures and harden OTel super-linter patching by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3507 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3627 Update actions/checkout action to v7 by @plengauer in https://github.com/plengauer/Thoth/pull/3663 Update actions/setup-java action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3677 Pin dependencies by @plengauer in https://github.com/plengauer/Thoth/pull/3670 Update otel/opentelemetry-collector-contrib Docker tag to v0.155.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3681 Update Gradle to v9.6.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3674 Update actions/cache action to v5.1.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3675 Update actions/setup-python action to v6.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3678 Update github/gh-aw-actions action to v0.81.6 by @plengauer in https://github.com/plengauer/Thoth/pull/3680 Update actions/attest-build-provenance action to v4.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3672 Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3679 Update plengauer/opentelemetry-github action to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3682 Fix renovate of copilot instrumentation by @plengauer in https://github.com/plengauer/Thoth/pull/3684 Update actions/setup-dotnet action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3676 Update Demo injection_deep_java by @plengauer in https://github.com/plengauer/Thoth/pull/3686 Update Demo _complex_download_github_releases by @plengauer in https://github.com/plengauer/Thoth/pull/3687 Update Demo injection_deep_node by @plengauer in https://github.com/plengauer/Thoth/pull/3688 Update Demo injection_inner_xargs_parallel by @plengauer in https://github.com/plengauer/Thoth/pull/3689 Update Demo observe_subprocesses by @plengauer in https://github.com/plengauer/Thoth/pull/3690 Update Demo injection_deep_python by @plengauer in https://github.com/plengauer/Thoth/pull/3691 Update Demo injection_docker_renovate by @plengauer in https://github.com/plengauer/Thoth/pull/3692 Deploy OpenTelemetry by @plengauer in https://github.com/plengauer/Thoth/pull/3685 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3709 Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 by @plengauer in https://github.com/plengauer/Thoth/pull/3705 Update docker/setup-buildx-action action to v4.2.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3707 Update github/codeql-action action to v4.36.3 by @plengauer in https://github.com/plengauer/Thoth/pull/3706 Update github/gh-aw-actions action to v0.82.2 by @plengauer in https://github.com/plengauer/Thoth/pull/3697 Unbreak agentic workflow recompilation with current gh-aw schema by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3704 Re-disable slim images by @plengauer in https://github.com/plengauer/Thoth/pull/3703 Update plengauer/autorerun action to v0.38.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3702 Update docker/build-push-action action to v7.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3700 Update actions/cache action to v6 by @plengauer in https://github.com/plengauer/Thoth/pull/3683 Update dependency traceloop-sdk to v0.62.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3695 Update renovatebot/github-action action to v46.1.17 by @plengauer in https://github.com/plengauer/Thoth/pull/3694 Update dependency org.junit.jupiter:junit-jupiter to v6.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3693 Rename quality job by @plengauer in https://github.com/plengauer/Thoth/pull/3696 Automatic Version Bump by @plengauer in https://github.com/plengauer/Thoth/pull/3698 Full Changelog: https://github.com/plengauer/Thoth/compare/v5...v5.59.0
July 6, 2026
Multi-Style Contribution Snake
Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v06.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐍 Multi-Style Snake Daily Update Automated daily release to the GitHub Marketplace.
Version Details:
Tag: v06.07.26 Release Date: $(date +’%A, %B %d, 20%y') Included Features:
5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds) Automated Month Labels above grids Dynamic Username Detection Auto-generated Asset Gallery
July 6, 2026
websec-validator
Version updated for https://github.com/raccioly/websec-validator to version v0.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor: the browser-vuln trio (XSS / clickjacking / CSRF) closes the classic-web-vuln gap, and a new enterprise / CI integration surface turns websec from a CLI-a-human-runs into a truth source a pipeline, dashboard, or any MCP agent can consume — SARIF, a --fail-on gate, git-diff baselining, a GitHub Action, an MCP server, and versioned output schemas. All stdlib, zero new runtime deps.
July 6, 2026
SpecGuard CI
Version updated for https://github.com/Sawaiz-zip/spec-guard to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed SpecGuard v0.4.0 Semantic governance gate for spec files — classifies PR changes against a locked project goal/scope and blocks unauthorized drift.
Highlights since v0.3.0 GitHub App — native check runs, fork-PR governance, and agent-identity handling for PRs that don’t come through the classic CI workflow (specs/006-github-app/) Advanced governance — section-level locking (govern just part of a file), monorepo multi-scope support (independent verdicts per package), and audit-trail JSON export (specs/007-advanced/) Approval commands — /specguard approve comment command and MCP containment for agent-driven approvals (specs/005-approval-commands/) Version metadata now consistent across pyproject.toml, __init__.py, and action.yml (all 0.4.0) Using this release - uses: Sawaiz-zip/spec-guard@v0 with: anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }} specguard-ci==0.4.0 is published on PyPI; the composite action pins to it directly.
July 6, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.16.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.16.0 Released 2026-07-05.
An output-economy and worker-reliability release: response-style profiles wired end to end, ledger-attributed savings you can recompute, a three-arm cost-and-quality A/B harness, proactive context compaction with signed receipts, schema-enforced worker outcomes, and pinned team manifests. Plus a batch of contributor reliability fixes.
July 6, 2026
Jekyll Redirects for Cloudflare
Version updated for https://github.com/SocksTheWolf/jekyll-cloudflare-redirects to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Just some minor logging changes, nothing major. Should be the final release for awhile.
July 6, 2026
Papyrus Markdown Export
Version updated for https://github.com/thomas-worm/papyrus-export-markdown to version v1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed papyrus-export-markdown This initial release provides a GitHub action that can export documentation from Papyrus projects in Markdown format. It iterates over a package tree and exports documentation and diagrams.
July 6, 2026
Auto Version
Version updated for https://github.com/twopow/auto-version-action to version v1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/twopow/auto-version-action/compare/v1...v1.4
July 5, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.2
July 5, 2026
IsReadyAI — readiness audit
Version updated for https://github.com/isreadyai/audit-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump actions to node24 versions (de249af) fix: marketplace-compliant description (fd40855) feat: initial action release tree (63ef75c)
July 5, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.81.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.81.2 (2026-07-05) Bug Fixes (mcp): do not cache error tool results (BZ-664 follow-up) (8f876dc)
July 5, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.19.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added runner lsp completes [tasks.overrides] entry keys with the project’s own task names (discovered from the document’s directory, same detection as the CLI), each carrying its source and description. Works both under the [tasks.overrides] header and as a dotted overrides.<task> key in [tasks]; names that aren’t bare TOML keys (e.g. build:web) insert quoted. Dotted overrides.<task> = values now complete the source-label vocabulary like their [tasks.overrides] equivalents. runner lsp key completions scaffold the value shape the field’s schema type calls for, when the client supports snippets: array fields insert pms = ["|"], string fields node = "|", others a bare tab stop; table fields continue the dotted key path (overrides.), which re-triggers completion. Clients without snippet support keep the plain name = insert. Fixed runner lsp no longer offers field completions after a dotted key (group_output. suggested the section’s whole field list; TOML reads the dot as a key path, and no section has enumerable sub-keys). Key completions also now carry an explicit text edit replacing the typed token, so a completion accepted from a stale list (e.g. left open across a backspace) substitutes the token instead of pasting after it (group_outputgroup_output =). runner lsp value completions inside an open string literal (prefer = ["ba) insert the bare word instead of a quoted one — the quotes are already typed (and auto-paired), so accepting previously produced ""bacon"". runner lsp is now comment-aware: no completions or hover at or after a # (whole-line or trailing); a # inside a string literal still isn’t treated as a comment. What’s Changed fix(lsp): dotted-key completion fixes + complete [tasks.overrides] keys with project task names by @kjanat in https://github.com/kjanat/runner/pull/85 Full Changelog: https://github.com/kjanat/runner/compare/v0.19.0...v0.19.1
July 5, 2026
conventional-semver
Version updated for https://github.com/logi-camp/conventional-semver to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.1.0 — Prerelease Support New Features Prerelease versioning — New prerelease input to generate tags like v1.3.0-rc.1 or v1.3.0-rc.a1b2c3d. Prerelease identifier modes — numbered (auto-incrementing rc.1, rc.2, …) or sha (commit hash-based). SHA suffix control — include_sha input: auto (prerelease only), true, or false. New Outputs base_version — Base version without prerelease suffix (e.g. 1.3.0) base_version_tag — Base version tag with prefix (e.g. v1.3.0) rc_number — The prerelease identifier number or SHA Improvements Expanded test suite with dedicated prerelease test cases Improved test output formatting and helper utilities Usage - uses: Logiconamp/conventional-semver@v1.1.0 with: prerelease: rc prerelease_identifier: numbered # or sha
July 5, 2026
ReviewGate
Version updated for https://github.com/LVTD-LLC/reviewgate to version v0.1.12.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Docs] Add ReviewGate Agent Skills by @rasulkireev in https://github.com/LVTD-LLC/reviewgate/pull/31 Highlights Added public check-reviewgate and reviewgate-loop agent skills. Documented npx skills add LVTD-LLC/reviewgate installation. Added comment-before-resolve guidance for agent repair loops. Added CI validation for public skill frontmatter, fenced Markdown, and shell snippets. Full Changelog: https://github.com/LVTD-LLC/reviewgate/compare/v0.1.11...v0.1.12
July 5, 2026
EIS — Upload Signals
Version updated for https://github.com/machuz/eis to version v2.20.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 12b8647cfb0faefd02757e3e2df9f56591ccf8b8 feat(attribution): expand + configure bot/AI co-author exclusion (#330) dc19e28d53502e089ce3cd4093238cfaca7eb2f7 feat(oss-map): monthly ingest + git/git (Linus) + identity pin + per-window streaming (#328)
July 5, 2026
Sentrik Gate
Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.6.0 Fixes the silent Linux binary. The v1.4.0 Linux binary produced no output and exited 0 due to a missing CLI entry-point invocation in the frozen build. All platform binaries in this release are built from a dedicated entry point and verified to produce output in CI before upload.
July 5, 2026
FHIR Validator
Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed npm tarball release for @records-fhir/validator@0.4.2. Synced from medvertical/records monorepo.
Install npm install @records-fhir/validator@0.4.2 What’s new in 0.4.2 Patch release for validator architecture boundaries, evidence policy, and maintainability after the 0.4.1 evidence release.
Added Added stable host and conformance package surfaces for embedding and evidence tooling, keeping repository consumers off deprecated implementation subpaths. Added dedupeIssuesWithTrace() so duplicate-suppression decisions expose the named policy rule that removed an issue. Added an explicit FHIR Schema runtime policy export that keeps the graph path evidence-only until Java/reference and dual-path gates justify promotion. Changed Hardened public-export and mirror-import architecture guards so new internal validator exports or repository imports fail fast. Split terminology remote CodeSystem budget handling out of the API client and kept the fail-open budget reason traceable. Split remote CodeSystem budget aggregation tests into focused coverage. Documentation Documented validator fallback, fail-open, fail-closed, legacy compatibility, and release-gate guardrails. Verification Verified with merged PR #252 CI, main CI, validator build, OSS boundary audit, OSS package smoke, architecture guards, focused Vitest suites, and npm publish dry-run. Matched npm tarballs @records-fhir/validator@0.4.2 — also tagged validator-v0.4.2 @records-fhir/validation-types@0.1.5 The matching GitHub Action release (if any) is published separately under tag v0.4.2 and is not auto-synced; this release covers the npm package only.
July 5, 2026
moult-action
Version updated for https://github.com/moult-rb/moult-rb to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add clone_group fingerprints to duplication findings and gate contributions by @GoodPie in https://github.com/moult-rb/moult-rb/pull/8 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.3.0...v0.4.0
July 5, 2026
Agent Security Harness
Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Closes the honest gap flagged in Discussion #231 and named by the ACM SIGOPS ATC ‘26 analysis Free-Riding the Agentic Web (arXiv:2605.30998).
Three of that paper’s four x402 attack primitives were already covered. The fourth — denial of settlement (consume the resource while withholding or delaying finality) — is a liveness attack with a different shape than a tamper→reject differential, so it was an untested gap. This release closes it: 3-of-4 → 4-of-4.
July 5, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.31.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 29 — four architectural false-positive fixes from a full audit of production reports (see RULES_CHANGELOG.md). The tandem “critical exfil” verdict was a symptom of broader engine gaps in where evidence is trusted; each class is fixed at the demotion layer so recall is preserved (efficacy + FP floors stay at 0): Example/demo/benchmark scaffolding (examples/, demo/, samples/, .env.example templates) is demoted to needs_review — it ships as illustration, not the component’s own runtime behavior. Also blocks such scaffolding from feeding ST-COMBO-EXFIL. Prompt-injection phrases inside structured-data values (.json / .yaml / .toml fixtures, scenario/eval data) are demoted — a string in a data blob is not an agent-facing instruction. MCP manifests are excluded (a tool description there is an instruction surface), so injection in mcp.json still scores. Over-broad MCP scope (ST-MCP-OVERBROAD-SCOPE) now only applies in an MCP context and ignores file-path globs (**/*.ts, .github/**) — a build-tool angular.json / greptile.json scope key is no longer misread as a permission wildcard. Net effect on audited projects: nopua high→low, ECC low/0, browser-use scaffold FP removed (real findings kept), and the tandem false “critical/malicious” collapses to medium/not-malicious.
July 5, 2026
pipewell-confluence-publisher
Version updated for https://github.com/pipewell/confluence-publisher to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What changed Manifest write-back now handled by the action itself.
Previously, the consuming repo’s workflow was responsible for committing updated page IDs back to confluence-manifest.yaml after new pages were created. This required a direct push to main, which broke when branch protection was enabled.
July 5, 2026
Drawio Export Action
Version updated for https://github.com/rlespinasse/drawio-export-action to version v2.52.0.
This action is used across all versions by 124 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.52.0 (2026-07-05) Features bump actions/checkout from 6 to 7 in the dependencies group (#104) (05de7b5)
July 5, 2026
Overleaf Resume Syncer
Version updated for https://github.com/sahitya1903/resume-syncer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refactor Overleaf parser, rename portfolio variables to external, and update docs
What’s Changed Refactor Overleaf parser, rename portfolio variables to external, and update docs by @sahitya1903 in https://github.com/sahitya1903/resume-syncer/pull/1 New Contributors @sahitya1903 made their first contribution in https://github.com/sahitya1903/resume-syncer/pull/1 Full Changelog: https://github.com/sahitya1903/resume-syncer/compare/v1...v1.0.1
July 5, 2026
Docker Compose Cache
Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/303 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.15...v1.8.16
July 5, 2026
Vulnerability Spoiler Alert
Version updated for https://github.com/spaceraccoon/vulnerability-spoiler-alert-action to version v1.6.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed refactor: diff truncation by @spaceraccoon in https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/21 Full Changelog: https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.5.0...v1.6.0
July 5, 2026
GitGalaxy Scanner
Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release represents a massive architectural maturation for GitGalaxy. The primary focus of v2.3.0 is the total alignment of the core parsing engine with formal, enterprise-grade DevSecOps terminology, alongside a complete overhaul of the CI/CD ingestion pipelines for air-gapped resilience and absolute data provenance.
July 5, 2026
DiffGate Review Triage
Version updated for https://github.com/srbsa/diffgate to version v0.7.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed release: 0.7.11 — finding-led positioning + PR-trail study post (9f9b019) release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373) fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0) release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9) release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc) release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf) fix: action.yml name collision + description over Marketplace’s 125-char cap (05227d2) fix: shorten server.json description under the MCP registry’s 100-char cap (2a4ada1) release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6) release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd)
July 5, 2026
pinprick-action
Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.1.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Updates the pinned pinprick version.
Defaults to pinprick 0.20.1 (was 0.20.0 in v0.4.0), pinned for deterministic runs. pinprick 0.20.1 restores the documented checksum-verification suppression for saved shell fetches that 0.20.0 dropped: an unversioned-URL download verified against a pinned digest within the three-line window is recorded as an allowed match again, including the piped manifest form. Pipe-to-shell and latest-URL findings remain exempt. The action’s behavior, inputs, and permissions are unchanged. See the README for usage.
July 5, 2026
Pi Review Agent
Version updated for https://github.com/sun-praise/pi-review-agent to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Fixed Team mode now respects the model input (#16). Previously the model was registered into the LiteLLM provider but never forwarded to runReview, so every persona and the coordinator fell back to the hardcoded default deepseek-v4-flash and failed for any non-default model such as mimo-v2.5. Single mode model input also fixed: it had the same omission and would fail for non-default models because the provider only registers the user-selected model. Verification Tested end-to-end in PR #18 with team: quality:1,security:1,performance:1 and model: mimo-v2.5: all three personas plus the coordinator completed successfully and posted a review comment. New Contributors None.
July 5, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.0.
This action is used across all versions by 131 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This setup-tombi release matches tombi v1.2.0.
Full Changelog: https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.0
July 5, 2026
configure-huawei-cloud-credentials
Version updated for https://github.com/vbem/configure-huawei-cloud-credentials to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/configure-huawei-cloud-credentials/compare/v1.0.0...v1.0.1
July 5, 2026
HumaneProxy Safety Benchmark
Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights 🔭 OpenTelemetry distributed tracing (#7) — export pipeline traces to Jaeger, Grafana Tempo, or Datadog via the new [telemetry] extra. Every request produces a pipeline.classify span with privacy-safe attributes (category, score, stage reached, message hash — never raw text). Zero overhead when disabled. 🌍 Region-aware care response — set safety.categories.self_harm.region: "IN" (any ISO country code) to surface that country’s crisis resources first, while always keeping the full international list. ☎️ Crisis helplines for new countries (#26) — Japan, South Korea, Spain, Italy, Mexico, New Zealand and more join the existing US/IN/GB/AU/CA/DE/FR/BR/ZA resources. 🗄️ Storage-backend consistency (#37) — the admin API, CLI, and MCP tools now route through the storage factory instead of raw SQLite, so Redis and PostgreSQL deployments see the same data everywhere. 📊 Query upgrades — escalation queries support date filtering (date_from/date_to) and sorting across all three backends. Fixed Multimodal content arrays: /chat extracts text from OpenAI-style content parts and no longer errors on string or malformed message content (#44, #45, #48). Empty /chat request bodies return a clean 400 (#41). CodeQL SQL-injection alerts resolved with statically generated SQL templates; timezone conversion and CSV triggers serialization fixed in escalation export. Security Admin Bearer-token comparison hardened against timing attacks with hmac.compare_digest (#18, #21). HTTP MCP hardened: binds to 127.0.0.1 by default, warns on public binds without a token, supports Bearer auth via HUMANE_PROXY_ADMIN_KEY, and bounds audit-log queries (#17). Docs & Tests Mermaid.js architecture diagram, README table of contents, corrected Stage-1 transition labels. New test coverage: Unicode/leet-speak heuristic edge cases, pipeline config validation, malformed payloads, decay-weighted-mean edge cases. Full Changelog: https://github.com/Vishisht16/Humane-Proxy/compare/v0.4.0...v0.5.0
July 5, 2026
Setup vp
Version updated for https://github.com/voidzero-dev/setup-vp to version v1.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): update dependency vite-plus to v0.2.2 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/104 feat: add GitLab CI/CD integration for setup-vp by @naokihaba in https://github.com/voidzero-dev/setup-vp/pull/97 New Contributors @naokihaba made their first contribution in https://github.com/voidzero-dev/setup-vp/pull/97 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.14.0...v1.15.0
July 5, 2026
Decionis Action Gate
Version updated for https://github.com/decionis/govern to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ⚡ Performance Local policy engine: the committed ```decionis rules block in DECIONIS_POLICY.md is evaluated in-process in microseconds, faithfully mirroring the platform evaluator. Deterministic allow/block verdicts act immediately; the API call becomes an async notarization off the critical path (signed dossiers, verify URLs, and badges still arrive). New local-eval input: auto (default) / strict (fully offline) / off (v1.8 behavior). Speculative shadow mode: run commands start immediately while the verdict resolves in the background — the gate adds ~zero latency. The step’s exit code is always the command’s; evaluation failures are notices. Shadow can no longer fail a build for any reason, and unconfigured gates (no secrets yet) are inert. Every run logs a Decionis timing — line so the speedups are visible. 🔧 Correctness API outcome normalization (APPROVE→allow, REJECT→block, REQUIRE_REVIEW→review) — enforce-mode run gating and fail-on now work against the live API vocabulary. New outputs: decision-source (local/api) and verdict-mismatch (local verdict vs notarizing API verdict, with a ::warning::). Example policies and the installer template set explicit rule priority and "domain": "*" so committed policies actually fire. 🚀 Onboarding install.sh ships in the repo: curl -fsSL https://decionis.com/govern/install.sh | sh -s -- --pr --inject writes a shadow workflow + starter policy, injects observe-only (continue-on-error) gate steps into existing workflows, and opens the onboarding PR. Badge/verify URLs pin the policy revision: &policy=sha256:<hash>. ✅ Compatibility All existing inputs/outputs unchanged; repos without a rules block see no decision-flow change. 143 tests, including end-to-end timing proofs against a mock API.
July 5, 2026
Zabbly Incus for GitHub Actions
Version updated for https://github.com/dionysius/incus-zabbly-actions to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dionysius/incus-zabbly-actions/compare/v1...v1.0.4
July 5, 2026
MUADDIB Scanner
Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.157.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Mutes the BURST PRE-ALERT Discord webhook by default (~700x/day, anti-corrélé avec les vrais incidents). Re-enable via MUADDIB_BURST_PREALERT_WEBHOOK=1. Console log + stats du daily summary inchangés.
July 5, 2026
DoesQA Trigger
Version updated for https://github.com/Does-QA/action to version v1.1.29.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.
July 5, 2026
Setup Umka
Version updated for https://github.com/fabasoad/setup-umka-action to version v1.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/148 fix: issue found by markdownlint by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/149 chore(deps): bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/150 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-umka-action/pull/151 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/152 Full Changelog: https://github.com/fabasoad/setup-umka-action/compare/v1.5.1...v1.5.2
July 5, 2026
Ansible Molecule
Version updated for https://github.com/gofrolist/molecule-action to version v2.7.103.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.7.103 (2026-07-04) Bug Fixes deps: Bump ansible-lint from 26.4.0 to 26.6.0 (12f1ba1)
deps: Bump docker/build-push-action from 7.2.0 to 7.3.0 (3c32800)
deps: Bump docker/login-action from 4.2.0 to 4.3.0 (a0106d0)
deps: Bump docker/metadata-action from 6.1.0 to 6.2.0 (bc9c924)
July 5, 2026
Setup poly CLI
Version updated for https://github.com/Goldziher/polylint to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.6.0
July 5, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.387.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/4ae7b7b1a9f2f618e9121afd1270023751de69ab with plugin-scanner 2.0.987.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.386...v1.2.387
July 5, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.387.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.387
July 5, 2026
JFrog Boost
Version updated for https://github.com/jfrog/boost to version v0.8.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.8.5
July 5, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added doctor --json overrides now reports every resolver override state except parent_group_open (internal runner-to-runner plumbing, never a user override): failure_policy, install_pms, output_grouping (group_output/github_group_parallel/parallel_grouped), prefer_sources, script_policy, and task_source_pins. Previously only pm/pm_by_ecosystem/runner/prefer_runners/fallback/ on_mismatch/explain/no_warnings/quiet were surfaced, so -k/-K, [tasks].prefer, [tasks.overrides], [install], and [github]/ [parallel] config could be set without doctor ever showing it. Changed Breaking: doctor --json and why --json now always emit the structured report (previously reachable via --schema-version 3); the flat v1/v2 shape is gone from both. --schema-version now only accepts 1; 2/3 are rejected. runner config init’s scaffold is now generated from RunnerConfig’s schemars metadata instead of hand-typed: section headers and their leading comments come straight from the section structs’ doc comments, and every enum-valued field’s inline hint (pm.node, pm.python, resolution.fallback, resolution.on_mismatch, install.scripts, task_runner.prefer) is generated from the same types the resolver parses those values with, not hand-typed prose. A config field, or an accepted value for one of these, can no longer ship without scaffold coverage — drift-guard tests fail the build instead. A few section descriptions read slightly differently as a result. FallbackPolicy, MismatchPolicy, and ScriptPolicy gained real label()/ALL (or SETTABLE) methods, replacing four separate hardcoded copies of their accepted strings (parse function, two display call sites, and now the scaffold) with one. Removed The v1/v2/v3 schema split. Not enough external adoption yet to justify carrying three versions per surface — today’s shape is the only one, retroactively called v1. Committed schema files dropped their version suffix (doctor.v3.schema.json → doctor.schema.json, etc.); the 10 superseded schema/example files are deleted.
July 5, 2026
pslrm Bump Action
Version updated for https://github.com/krymtkts/pslrm-bump-action to version v0.0.2.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Add skip-psresourceget-install input to skip PSResourceGet installation. Changed Avoid unconditional Microsoft.PowerShell.PSResourceGet install. Check if version 1.0.1+ exists. Create bump commits through GitHub’s Git Database API so GitHub can mark them as verified. Notes Documentation now recommends GITHUB_TOKEN for most repositories. GitHub now allows workflows to run for approved pull requests created by github-actions[bot]. Use a PAT when subsequent workflows must run automatically without human approval.
July 5, 2026
Nox Security Scanner
Version updated for https://github.com/Nox-HQ/nox to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.6.0 (2026-07-05T11:53:33Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Others d7b896556efae04fd506e5073a24f939f4f451b4 docs(readme): refresh for v1.5.0 (#166) 91c967a5a94b90137ec7bb5e95de6f952385c239 docs(usage): document v1.5.0 commands (#167) e41f301347d60e6a6843868fca34df9d482108cb release: v1.6.0 (#174) Full Changelog: https://github.com/nox-hq/nox/compare/v1.5.0...v1.6.0
July 5, 2026
Podcast Generator NS
Version updated for https://github.com/nshportun/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/nshportun/podcast-generator/commits/v1.0
July 5, 2026
Changelog Bot Runner Nyaomaru
Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(changelog): 0.6.3 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/154 feat: improve why template extraction by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/155 Release: 0.6.4 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/156 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.4
July 5, 2026
lacuna-cli
Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.2.4...v0.3.0
July 5, 2026
J-Bot Code Review
Version updated for https://github.com/pgup-ai/jbot-review-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Marketplace release of J-Bot Review — an open-source agentic PR reviewer that runs as a single GitHub Action inside your own CI, with a model you already pay for.
July 5, 2026
PingRoom Notify
Version updated for https://github.com/pingroom/cli to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Turn a human decision into a shell gate. This release adds the Question commands to the CLI, alongside the existing ping.
New commands ask — ask a human a question in a room; with --wait, block until they tap an answer on their phone. Prints the chosen value to stdout and encodes the outcome in the exit code (0 answered · 3 expired · 4 cancelled), so it drops straight into a shell conditional. watch — block on an existing question until it resolves. list — list your agent’s questions by state. cancel — withdraw a pending question. if [ "$(pingroom ask --token "$PINGROOM_TOKEN" --room ab12cd --wait -p 'Deploy 1.4.0 to production?')" = approve ]; then ./deploy-prod.sh fi The Action The PingRoom Notify action sends a ping on deploy/CI and now runs on @pingroom/cli@0.2.0:
July 5, 2026
FoundRuu Doctor
Version updated for https://github.com/Ruu5LP/foundruu to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Broaden doctor –deep document detection by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/16 Release 0.11.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/17 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.10.0...v0.11.0
July 5, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.15.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.15.0 Released 2026-07-05.
Feature release built around five community contributions by Shane Mattner (@shanemmattner), plus scheduler and test-infrastructure fixes.
Features Hold/release API (/orchestrator/holds): heartbeat-renewed leases that keep the spawner alive while an external workflow driver is active, replacing the fixed quiescence settle timer. TTL is a grace window; expired holds release on their own. Operator docs in docs/operations/HOLDS.md. (#2218, thanks @shanemmattner) Explicit max_turns on TaskCreate: per-task turn budgets flow end to end to the adapter spawn, bypassing the complexity heuristic when set; bounded 1..10000 at the schema boundary; retries carry the value forward. Docs in docs/operations/MAX_TURNS.md. (#2217, thanks @shanemmattner) Per-agent run instrumentation: JSONL records for every LLM call, tool call, and conversation message, captured in real time via SDK hooks and anchored to the project root (not the per-task worktree). Docs in docs/operations/INSTRUMENTATION.md. (#2219, thanks @shanemmattner) Council-of-agents redesign: per-member cost attribution, judge synthesis over candidate outputs, enable_thinking=false injected for Qwen models served from Alibaba Cloud endpoints (hostname-suffix detection), and BERNSTEIN_BUILTIN_ALLOW_RUN_COMMAND passthrough in env isolation. (#2220, thanks @shanemmattner) Inline role_model_policy.<role>.council seed blocks now forward into the runner manifest, behaving identically to the councils/*.yaml file convention. (#2231) Fixes Model selection no longer falls back to hardcoded model strings: every selection flows from configuration, and unconfigured paths raise ModelNotConfiguredError instead of silently guessing. (#2216, thanks @shanemmattner) Critical-path priority boost applies on the first spawn batch, so a low-priority dependency of a high-priority task is claimed first. (#2233) Worker exit codes: when the whole process group receives SIGINT, the worker no longer re-forwards the signal into the child’s interpreter shutdown window, so it reports the child handler’s exit code instead of 130. (#2238) Five integration tests repaired and re-enabled after root-causing failures that predated this cycle. (#2232) Internal Unit coverage for the council runner path. (#2230) Log-injection sanitization on hold fields; scanner findings resolved across instrumentation and council logging. (#2229)
July 5, 2026
Setup UniRTM
Version updated for https://github.com/snowdreamtech/setup-unirtm to version v0.5.0.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.5.0 (2026-07-05) Features add job summary output (23587ed) atomic caching to prevent corrupted cache on install failure (2f09505) Bug Fixes polyfill import.meta.url for esbuild CJS bundle (3ff3077) remove esbuild minify to fix createRequire(import.meta.url) cjs interop bug (0be14b5) temporarily disable pip auto-detection and integration test (9d019b4)
July 5, 2026
Generate Pong SVGs
Version updated for https://github.com/st1vms/PongSVG to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed CHANGELOG New modes! avatar, follower, star
July 5, 2026
SignalBrain receipt gate
Version updated for https://github.com/whitestone1121-web/signalbrain to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #12 from whitestone1121-web/codex/release-0.1.4-license (c809682) release-0.1.4-license-detection (7d1c13b) Merge pull request #11 from whitestone1121-web/codex/release-0.1.3-readiness (07056b8) release: prepare SignalBrain 0.1.3 (9185882) Merge pull request #10 from whitestone1121-web/codex/integrity-docs-hardening (f7cb57d) docs: define SignalBrain integrity boundary (4ac82fc) docs: GitHub mirror of the confidence-inversion essay (AI-readable) (01e1382) docs: emission guide wrongly claimed pipe support — spec and scorer disagree (1119308) study: pre-register the Overclaiming Report task sample (n=50, seed 58) (372b069) docs: link the live confidence-inversion essay (d2247ac)
July 5, 2026
backlog-to-pr
Version updated for https://github.com/wrbl606/backlog.md-to-pr to version 0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.3...0.0.4
July 5, 2026
Intent Guarantor — Differential Enforcement
Version updated for https://github.com/zAnshn/guarantor to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Intent Guarantor v0.1.0 — first public release A tenant-isolation gate for Next.js + Supabase/Prisma/Drizzle apps: it flags cross-tenant data-leak (IDOR) bugs — the class that’s #1 on the OWASP API Top 10 and that generic scanners miss.
July 5, 2026
Doc Detective
Version updated for https://github.com/doc-detective/github-action to version v1.6.1.
This action is used across all versions by 9 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: reload udev rules before triggering when enabling KVM (#72) Follow-up to v1.6.0. enableLinuxKvm now runs udevadm control --reload-rules before udevadm trigger, so the freshly-written kvm rule is actually loaded and /dev/kvm becomes accessible — without it the android: auto KVM setup was a no-op and Android contexts still SKIPped.
July 5, 2026
AgentGuard Security Scan
Version updated for https://github.com/dockfixlabs/agentguard to version v0.6.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ASI-STEGANO-INJECT: 6th novel rule. 19 rules, 102 tests, 50 benchmark.
Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.6.6...v0.6.8
July 5, 2026
terraform-monorepo-action
Version updated for https://github.com/fr12k/terraform-monorepo-action to version v3.0.10.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump eslint from 10.2.1 to 10.3.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/169 build(deps): bump @actions/core from 2.0.2 to 3.0.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/167 build(deps-dev): bump eslint from 10.3.0 to 10.4.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/175 build(deps-dev): bump @types/node from 25.6.0 to 25.9.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/174 build(deps): bump @actions/github from 9.1.0 to 9.1.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/168 build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/180 build(deps-dev): bump eslint from 10.4.1 to 10.6.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/184 build(deps-dev): bump @types/node from 25.9.1 to 26.0.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/181 build(deps-dev): bump prettier from 3.8.3 to 3.9.4 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/185 build(deps): bump undici from 6.25.0 to 6.27.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/182 Full Changelog: https://github.com/fr12k/terraform-monorepo-action/compare/v3.0.9...v3.0.10
July 5, 2026
RunRight CI Resource Monitor
Version updated for https://github.com/gbudjeakp/run-right to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v1.5.0 - Email Notifications, Analytics Dashboard, Alerts UX New Features Email notification destination - SMTP support with demo fallback Analytics dashboard - Cost breakdown by repo/job/runner with trends Search bars for Alert Rules and Ownership tabs SSO support - SAML and OIDC authentication API keys management Backend EmailChannel adapter in notification package SMTP config via RUNRIGHT_SMTP_* environment variables Analytics API endpoints Frontend Email tab in Destinations with subject prefix and recipients Analytics page with charts and filters Improved alert rules filtering Docs Added CHANGELOG.md Updated comparison page with honest feature matrix Added SMTP environment variables to install docs Full Changelog: https://github.com/gbudjeakp/run-right/compare/v1.2.3...v1.5.0
July 5, 2026
Setup poly CLI
Version updated for https://github.com/Goldziher/polylint to version v0.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.5.1
July 5, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.386.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/e96dd6853a6672b8a87ea1b9f9f183add027bb95 with plugin-scanner 2.0.986.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.385...v1.2.386
July 5, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.386.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.386
July 5, 2026
hide-comment
Version updated for https://github.com/int128/hide-comment-action to version v1.64.0.
This action is used across all versions by 227 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: int128/hide-comment-action@769d2f65928cb6477a9993aab4ed7a02c33f4588 # v1.64.0 What’s Changed chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1643 chore(deps): update dependency @biomejs/biome to v2.5.1 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1642 chore(deps): update int128/wait-for-workflows-action action to v1.83.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1644 chore(deps): update node.js to v24.18.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1645 chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1647 chore(deps): update dependency js-yaml to v4.3.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1646 chore(deps): update pnpm to v11.9.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1648 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1649 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.63.0...v1.64.0
July 5, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.1
July 5, 2026
probelock gate
Version updated for https://github.com/kelkalot/probelock to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Make –tools optional when using traces/mined by @kelkalot in https://github.com/kelkalot/probelock/pull/3 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v0.3.1
July 5, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.18.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed The v0.18.0 npm packages spawn-failed with EACCES: the platform packages’ new explicit bin field disabled directories.bin linking, so npm no longer marked the native binaries executable at install — breaking both npx @runner-run/<platform> … and the runner-run facade. Platform bin entries now point directly at the native binaries and expose both commands (npx --package=@runner-run/<platform> runner … and … run …); the launcher shim and the erroneous bin + directories.bin combination are gone. Versions up to 0.17.0 were unaffected; 0.18.0 is deprecated on npm. The npm dist artifact now crosses the build→publish handoff as a tarball so unix file modes survive the zip-based artifact store; the publish job refuses non-executable binaries and smoke-tests the packed tarballs (install + execute every bin) before publishing. Full Changelog: https://github.com/kjanat/runner/compare/v0.18.0...v0.18.1
July 5, 2026
Skilldrift — Skills Drift Monitor
Version updated for https://github.com/kpab/skilldrift to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 1ecdde4a554e5e2817954060cd83e326217bf5f6 action.yml: marketplace公開向けにname一意化とdescription短縮
July 5, 2026
invAIriant audit gate
Version updated for https://github.com/mindicator/invAIriant to version v0.2.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The CLI seatbelt now uses semantic color on a real terminal — green ✓/OK, red ✗/FAILED/S0, amber S1 — so a live terminal recording reads clearly. Color is emitted only on a TTY (honoring NO_COLOR); piped and CI output stay byte-for-byte plain, so exit codes and parsed output are unaffected. Auto-published to PyPI via Trusted Publishing. No new lenses; the CLI still performs no judgment.
July 5, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.89.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 5, 2026
DeepRabbit Code Review
Version updated for https://github.com/n0namedeveloper/DeepRabbit to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor stuctural rework of comments. Should look perfect by now.
July 5, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.14.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.14 (2026-07-04)
July 5, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.8
Resolve Method Calls To Methods, Not Constructors Sharing The Class Name
Maintain Map Insertion Order In Builtins So values() And keySet() See Every Entry
July 5, 2026
Next CalVer Version
Version updated for https://github.com/okaryo/calver to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed Use @actions/github and GitHub matching refs to load only tags for the resolved release date, reducing API requests in repositories with many tags. Change previous-version to report the latest matching version for the resolved date only. Full Changelog: https://github.com/okaryo/calver/compare/v1.0.0...v1.1.0
July 5, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.29.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added skilltotal inventory --sbom — AI-BOM export. The installed-component inventory (every MCP server and skill your agent hosts reference) as a standard CycloneDX 1.6 JSON document, ready for Dependency-Track / compliance pipelines. Components carry a purl when the source is an npm:/pypi: spec and the SkillTotal scan verdict as skilltotal:* properties (host, kind, risk level/score, verdict). New pure module skilltotal.sbom. skilltotal scan --provenance — opt-in registry provenance signals. For npm: / pypi: sources: recently published (<30 days), deprecated (npm) / yanked (PyPI), no recent releases (>3 years), no repository link. Registry metadata is context about a component, not component content, so the component-only invariant holds: opt-in flag, fetched at the CLI layer (never inside the engine), and emitted only as needs_review — never findings, never the score, never the verdict. New pure module skilltotal.provenance.
July 5, 2026
PR Explainer AI
Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release for PR Explainer AI.\n\n- Add a minimal success message to the PR comment\n- Keep the artifact and run link concise and readable\n- Preserve the existing v1.0.1 pipeline and compatibility fixes
July 5, 2026
MaintainerOps AI
Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Adds maintainerops demo, a no-key/no-token/no-fixture CLI path that prints a real offline review packet. Demo mode is forced offline and rejects live GitHub/model options. Updates README, Marketplace notes, and external feedback docs so testers can try a packet with one npm command. Records an API-free security diff review for the demo path. Verification node dist/cli.js demo --format markdown node dist/cli.js demo --format json node dist/cli.js demo --model gpt-4o-mini fails closed node dist/cli.js demo --repo owner/repo fails closed npm run format:check git diff --check npm run verify PR #79 checks passed post-merge CodeQL passed Safety The demo command does not require OPENAI_API_KEY, GITHUB_TOKEN, repository access, or local fixture files. It does not modify GitHub state.
July 5, 2026
Setup Swamp
Version updated for https://github.com/systeminit/setup-swamp to version v0.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hide the whoami information from the output
July 5, 2026
overllm
Version updated for https://github.com/theadamdanielsson/overllm to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Recall improvements + one new rule, each validated on ~14k files of real code (framework-heavy and amateur) with no new false positives.
Matured call detection — follow a model through composition. LangChain chain.invoke(...) and bound-model .invoke(...) are now detected (an LCEL | pipe, .with_structured_output(), or an alias that composes a known model). A prompt | parser chain (no model) or a dict | dict merge is not tracked — precise. langchain detection 385→492. kwargs-splat — create(**params) on the unambiguous chains. Embeddings — embeddings.create in a per-item loop → llm-in-loop. Module-constant prompts — a prompt/model held in a top-level constant used inside a function is resolved. New rule json-mode-missing-json — response_format=json_object with a static prompt lacking “json” is a provable OpenAI 400 (fires only when the absence is provable). 155 tests. Precision held: amateur-corpus findings byte-identical to 0.6.2.
July 5, 2026
compose-lint
Version updated for https://github.com/tmatens/compose-lint to version v0.13.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Validated profiles must declare immutable version tags. The profile ci-smoke gate (scripts/validate_profiles.py) now rejects a status: validated profile whose applies_to.tags includes a mutable rolling tag (latest, stable, edge, main, nightly, …): such a tag points to a different image over time, so a derivation done against it cannot be trusted to still apply to the image a consumer later pulls. Exploratory profiles are unaffected, and no existing catalog profile uses a mutable tag, so this guards against a future mistake without changing current data. Profile schema 1.3: app_tier_verified. An optional top-level block on a profile recording that the whole hardening was verified at the service level — the multi-container stack brought up with every dimension applied and a real service-level check passed — a stronger signal than the per-dimension workload, which exercises only one container. Fields: service, service_version, method, check, verified_date, result, and an optional over_hardening (applied + result) that proves the check catches a too-tight config (not a rubber stamp). Requires status: validated (schema) and result: pass (ci-smoke gate). Optional and additive — all 1.0–1.2 documents remain valid, and it never substitutes for the per-dimension validated_via evidence. ADR-017 §10. Fixed Profile-enrichment hints no longer collapse across services in text output. The fix-block dedup keyed on rule_id alone, so when two services were flagged by the same rule but enrichment gave them different image-specific guidance (e.g. postgres → cap_add: [CHOWN, DAC_OVERRIDE, SETGID, SETUID], caddy → cap_add: [NET_BIND_SERVICE]), the second service was rendered (see fix above) — pointing at the first service’s wrong-image recommendation. The dedup now keys on (rule_id, fix, references), so distinct hints each print in full while identical fixes still collapse. Changed Profile enrichment is now labeled experimental. The feature is already opt-in and off by default (profiles.enabled); this makes its provisional status explicit. When enrichment is active, compose-lint prints a one-line stderr reminder that fix recommendations are advisory, derived for a specific invocation, and not validated against your runtime — and the config docs mark the section experimental. No behavior change to the findings themselves. Clearer profile-enrichment caveat. The provenance tail not independently verified here is replaced with compose-lint can't see your runtime, confirm it fits your setup — it names the actual limit (a static linter reads the compose text, not the running container, and can’t confirm the recommendation matches your invocation) rather than a vague disclaimer. Added Profile schema 1.2 (ADR-017 §9): an optional derivation.run_config block recording the invocation a minimum was derived under — user, command, entrypoint, network, pid, devices, security_opt, mounts, and env (keys only, never values). A derived minimum is only valid for its invocation (postgres run with user: set skips the root→user drop and needs none of the startup caps a default-invocation profile lists), so a consumer can diff a target service against it and downgrade to a hint on divergence. Emitted by csd’s drop-test producer, not hand-authored. Additive — all 1.0/1.1 documents remain valid. Opt-in profile enrichment (ADR-017). Set profiles.enabled: true and point profiles.path at a catalog of container-sec-derive (csd) profiles you trust; findings from CL-0006/0007/0002/0011/0016 then gain image-specific fix guidance — e.g. the observed minimum cap_add for that image. Enrichment is advisory and additive only (it never creates, drops, or reclassifies a finding) and the hint is attributed and marked unverified. Off by default. Per ADR-017 §7, compose-lint ships no catalog of its own — the catalog is a user-configured external source, so the linter neither grows nor endorses profile data. Profile contribution path (ADR-017): scripts/validate_profiles.py (the ci-smoke gate — schema, validated/exploratory invariants, and workload-hash verification), a profile-validate CI job that runs it on catalog changes, and a contributor guide (docs/profiles.md).
July 5, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.704.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.704.3 Released 2026-07-04
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.704.1, interleaved on one runner against the pinned corpus (157 metrics compared).
July 4, 2026
Hwaro Deploy to Pages
Version updated for https://github.com/hahwul/hwaro to version v0.17.0.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.17.0 Added [outputs] config: extra per-page/section output formats (json, txt, xml, csv) from user templates/page.<fmt>.jinja / section.<fmt>.jinja, overridable per page via a front-matter outputs key (cascades), exposed as {{ alternate_output_tags }}, cache-aware under --cache Markdown render hooks: templates/hooks/render-{link,image,heading,codeblock}.html override element rendering (Hugo/Zola-style), no-op when absent; existing @//shortcode/srcset/anchor resolvers still run. See Render Hooks Fenced code block options after the language ({linenos=true, hl_lines="2-4 7", linenostart=5}) plus [highlight] line_numbers; mode = "server" bakes the result at build time, mode = "client" emits data-* attributes Opt-in inline markup behind [markdown] flags (off by default): ins (++), mark (==), sub (~), sup (^) Generalized {#id .class key=val} attribute blocks on headings and inline images ([markdown] attributes) First-class menu system (Hugo-style): [[menus.<name>]], per-language overrides, front-matter registration; exposed via site.menus/get_menu() with an active_path filter; doctor validates undefined parents and menu names hwaro init --wizard and hwaro new (no <path>) open interactive terminal wizards; archetypes gain a {{ description }} placeholder Scaffold design tokens (“Hwaro Ember” :root with light-dark() pairs, fluid type/space scales) and a header theme switcher (auto → light → dark, persisted, flash-free) across every styled scaffold just scaffold-previews: regenerate docs scaffold screenshots headlessly Changed hwaro init initializes immediately with defaults; --wizard opens the interactive flow (removed -y/--yes) Terminal output: the remaining commands (list/stats/validate/check-links/deploy/export/import/unused-assets/convert/platform/agents-md) adopt the ember language and shared glyph set; machine surfaces (--json, serve ready line, --version, exit codes) are byte-for-byte unchanged Scaffold design pass across docs/blog/book (~1,600 lines of duplicated dark CSS deleted) Removed The blog-dark, docs-dark, and book-dark scaffolds — scaffolds follow the OS scheme and ship a manual switcher; pin one permanently with :root { color-scheme: dark; } in css/style.css Fixed macOS release binaries shipped as portable .tar.gz archives with bundled OpenSSL, dropping the hardcoded Homebrew openssl@3 dependency Shortcodes: Jinja control tags ({% if %}, {% set %}) in block bodies no longer desync the nesting scan; mixed positional + named args no longer drop the positional value PWA service worker: offline→root navigation fallback restored across all three cache strategies llms-full.txt honors in_search_index = false Internal @/ links with a query string or anchor no longer double-escape & hwaro serve: authors front-matter edits update the taxonomy incrementally; equal-weight sections keep a stable prev/next order --cache: deleting a page regenerates the sitemap/feeds/search index even when no surviving page re-rendered Parallel builds surface sitemap/feed/search failures instead of exiting 0; closed section-list and shortcode-init fiber-safety gaps under -Dpreview_mt AMP: <img> with > inside a quoted attribute value converts without corrupting the markup Performance Flat N-page sites avoid an O(N²) render cost — section-page arrays and SEO/OG/canonical/JSON-LD strings are built only when the template’s static closure can reach them Parallel render workers read prewarmed Crinja caches lock-free (-Dpreview_mt); taxonomy generation reuses the running Builder instead of a second O(N) Crinja pass Markdown skips footnote/definition-list passes when the markers are absent; builds no longer run the markdown pipeline twice (dropped the legacy hook pre-pass) JS minification is no longer O(n²) on non-ASCII files (128KB CJK bundle: 59.5s → 9.6ms); HTML minifier compiles protected-tag patterns once at startup --cache: touched-but-identical files re-hashed once, page-bundle assets no longer recopied, lock-free hit/miss counters; serve incremental rebuilds render the affected set in parallel 404 page reuses render-phase template vars; --stream builds per-worker engines once per run; load_data() memoized per file mtime Full Changelog: https://github.com/hahwul/hwaro/compare/v0.16.0...v0.17.0
July 4, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.380.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/90c7ce1e7c3346d7c1d85d79ff61f8fd56adad8b with plugin-scanner 2.0.980.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.379...v1.2.380
July 4, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.380.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.380
July 4, 2026
Holon Solve
Version updated for https://github.com/holon-run/holon to version v0.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.26.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release introduces the Agent Template package and registry line: local and remote template sources, GitHub repository discovery, daemon sync and diagnostics APIs, web GUI template browsing, and template skill preinstallation. It also adds GitHub Actions-style skill uses shorthand, improves the web GUI skills/file experience, and fixes template/skill install edge cases plus several runtime and provider issues.
July 4, 2026
offsec-ai Security Scanner
Version updated for https://github.com/Htunn/offsec-ai to version v2.5.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688) chore: replace all example.com targets with simpleportchecker.com (676106d) fix: –format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8) fix: skip –timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd) chore: use Gemini public endpoint in ai-owasp-scan job (6a13857) fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41) fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327) chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12) fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc) fix: pin offsec-ai-action.yml to v2.5.3 (secrets expression fix) (c4a71c5)
July 4, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.0
July 4, 2026
Versionary Action
Version updated for https://github.com/jolars/versionary to version v0.32.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Features artifact-rules: support templated regex replacement (1bc89e5), closes #68 Bug Fixes pr: honor r-news format in single-package PR body (d8004c0) deps: bump vite to 8 and esbuild to 0.28.1 (b571e22)
July 4, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.17.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added FQN task syntax: the root:<source>#<name> identity that doctor --json / why --json print for a task is now runnable — run 'root:package.json#deno:importsmap' (the root: scope prefix is optional) dispatches that exact task. Every source label of every schema version round-trips, including v3’s cargo-alias, which previously named a task no syntax could invoke. runner why interprets its argument exactly like run does — qualified syntax (why deno:lint), FQN (why root:package.json#build), and the colon-name fallback below — so it explains the very dispatch run would perform instead of reporting “no candidates” for tokens run accepts. Makefile descriptions from the inline self-documenting form (build: deps ## Build the project), the idiom ## help targets are built on. The preceding-line ## doc form still wins when both are present. Changed A qualified or FQN miss (deno:nope, package.json#nope) is now a hard error in every path. Previously an FQN token fell through to the PM-exec fallback, where bunx/npx treated it as a package spec and resolved it off the network — a typo could hang on registry resolution or download an arbitrary package. Bare unmatched names still fall through; user/repo#ref package specs still work. Single runs and chain pre-validation (run -p/-s) report a qualified miss with one unified message, and miss errors add a note when a source’s task list failed to load (a broken package.json used to produce only a misleading did you mean …? hint). A CLI chain-failure flag now beats the opposite polarity from a lower layer: run -s a b -k with [chain] kill_on_fail = true in runner.toml keeps going instead of aborting with a cross-source conflict — the config polarity had no command-line escape hatch. Same-source conflicts (-k -K, both env vars, both config keys) still error. Boolean RUNNER_* env vars (RUNNER_QUIET, RUNNER_EXPLAIN, RUNNER_NO_WARNINGS, RUNNER_KEEP_GOING, RUNNER_KILL_ON_FAIL) warn and are ignored when set to an unrecognized token. RUNNER_KEEP_GOING=flase (typo’d “false”) used to silently read as truthy — the opposite of the intent. Recognized, case-insensitive: 1/true/yes/on and 0/false/no/off. Fixed package.json scripts whose names start with a source label (deno:importsmap, cargo:check, …) are reachable by their bare name again. The qualifier parser claimed the prefix (deno → deno.json), the qualified lookup missed, and dispatch fell through to PM-exec; an exact full-name match now wins on a qualified miss. A genuine deno.json task still outranks the colon-named script when both exist. Streaming parallel chains (run -p, the default outside GitHub Actions) no longer hang when a task exits but leaves a backgrounded descendant holding the inherited stdout/stderr pipe (some-daemon & exit 0). Pipe readers are now drained with the same bounded grace the grouped path already used, instead of an unbounded join that blocked until the descendant died. A try_wait error while polling a parallel chain no longer orphans the already-spawned sibling processes and their reader threads; both parallel paths route the error through the same kill-and-reap cleanup as a spawn failure. A malformed devEngines value in package.json (e.g. a Corepack-style string where the spec wants an object) no longer erases every script and the packageManager signal behind a false not valid JSON warning. The field degrades to “absent”; the rest of the manifest parses normally. The Taskfile fallback parser (used when the task binary is absent) is a real YAML parse now: quoted and namespaced task names ("build:prod":) are no longer silently dropped, and a Taskfile that fails to parse surfaces a failed to read tasks warning instead of silently yielding zero tasks. A Makefile target whose header appears twice (legal in make) is listed once instead of twice; a later documented duplicate still contributes the description when the first occurrence had none. Full Changelog: https://github.com/kjanat/runner/compare/v0.16.1...v0.17.0
July 4, 2026
Quorum consensus security scan
Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.8.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 9146db25b4fd57deb4446de10bfd5909f25431c6: Merge pull request #68 from Martinez1991/feat/rag-semantic-index (@Martinez1991) 1eb7ebfec1ef184043bb47c189a90af66229d4e9: Merge pull request #69 from Martinez1991/feat/advice-metrics (@Martinez1991) edaa5707bb5fd5867f3a42526505875a9bb3ca8e: Merge pull request #70 from Martinez1991/feat/action-advice-cache (@Martinez1991) a54b996adf53910362ad3d915753c64e4f0db24d: Merge pull request #71 from Martinez1991/feat/knowledge-expand (@Martinez1991) a93090e9ffff9bb05a77233465f006cb13a25694: Merge pull request #72 from Martinez1991/feat/advisor-evals (@Martinez1991) a70c6cfcb83736adb8102a4d1f05edafd7b30ebf: Merge pull request #73 from Martinez1991/feat/attest-knowledge (@Martinez1991) 58936fe1b14e9f937a6fd9ac3e0ad462f4d9bfa1: feat(action): expose advice-cache for reproducible AI advice across CI runs (@Martinez1991) 931c74c009a9c5a5204da2199735f675954a2124: feat(release): attest the advisory knowledge pack (SLSA provenance) (@Martinez1991) a6e45860d6ca5800623e4c87416a834ec93b3e26: feat: Prometheus metrics for the advisory layer (observability) (@Martinez1991) 63b490cc396d7d0845955c5184a7e31e0ead8b8b: feat: advise-index — bake embeddings into the OWASP corpus (semantic RAG) (@Martinez1991) 497624cb934d9aa486858733890123b743f38436: feat: advisor eval harness (deterministic quality + verify-the-fix rate) (@Martinez1991) 97e6ab512cc8146470e29f56e877e9a581a85ea0: feat: expand the advisory knowledge pack (Azure/GCP templates + OWASP corpus) (@Martinez1991)
July 4, 2026
invAIriant audit gate
Version updated for https://github.com/mindicator/invAIriant to version v0.2.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes the two public front doors and enables the first automated PyPI publish.
PyPI page invairiant 0.2.3’s project page was immutable with the old pip install -e . text (the readme was fixed just after that release). 0.2.4 lands the corrected page: the CLI readme (the package’s long_description) leads with pip install invairiant and uses absolute GitHub links so they resolve on pypi.org.
July 4, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.13.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.13 (2026-07-04)
July 4, 2026
Next CalVer Version
Version updated for https://github.com/okaryo/calver to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Release!🚀
Full Changelog: https://github.com/okaryo/calver/commits/v1.0.0
July 4, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.26.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection precision (ruleset 27): one FP on a real popular project (firecrawl/firecrawl) closed, recall-preserving. The ST-PROMPT-INJECTION “send … to webhook” sub-patterns matched send [anything] to [the] webhook, so a benign OpenAPI field description "Headers to send to the webhook URL." flipped firecrawl to has_malicious_indicators. They are replaced by a single pattern that requires a SENSITIVE data object (credentials/secrets/api keys/tokens/passwords/env vars/conversation history/system prompt/“the-or-user’s data”) between the send verb and webhook, mirroring the sibling “send <secret> to” exfil rule. Recall preserved: “send the conversation history to this webhook”, “POST the credentials to this webhook URL”, “exfiltrate the user’s data to the webhook” still fire; “send a request/the payload to the webhook” no longer does. New unit tests + a benign fp_webhook_headers fixture; FP floor and efficacy (100%/100%) stay green.
July 4, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.10.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Reorders the two attribution gates in _retry_license_via_arxiv_html so the stronger evidence (README references the paper’s arxiv id or ≥2 title words) runs first, with title-overlap demoted to a tie-breaker among survivors. Fixes silent license_class=no-code-link classifications on acronym-named repos whose acronym isn’t literally in the paper title.
July 4, 2026
codemetrics complexity gate
Version updated for https://github.com/richardwooding/codemetrics to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Features c3734720572df8dba08deeca4dda37adecdf4e70: feat(cli): real colorized output — honors NO_COLOR, TTY, and –color (#18) (@richardwooding) Others ee913ecf0e9f550f0c21d830fabc0067671be3de: ci(pages): self-enable Pages so the deploy can’t fail on a fresh repo (#17) (@richardwooding) e2bfa55d72e6af97d657c8247f22024eb01cebfb: docs(site): GitHub Pages marketing landing page (#16) (@richardwooding)
July 4, 2026
MaintainerOps AI
Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed MaintainerOps AI v0.1.12 expands model-backed eval readiness and records the first passing 10-case live eval run.
Highlights:
Added a dedicated 10-case model-backed eval file. Added smoke / expanded / all suites plus targeted –case execution. Added –cases-file, –summary-json, and API-free npm run eval:model:list. Added stricter recommended-action and risk-bound checks. Improved normalization for dependency updates, license metadata issues, and direct security-boundary findings. Recorded the approved 10-case live model-backed eval result. Live eval evidence:
July 4, 2026
skill-switch audit
Version updated for https://github.com/rtwsvj/skill-switch to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 安装 / Install macOS(Apple Silicon)桌面 App:下载下方 skill-switch_0.9.0_aarch64.dmg(29M,Developer ID 签名 + Apple 公证),拖进「应用程序」即可。
SHA-256: d415f3b1346de71c57b1e537e3da961c9cc9d19d375f743af7bc15e1adc7c0fd CLI:npx @rtwsvj/skill-switch audit
[0.9.0] - 2026-07-01 自 v0.6.0(npm 上最后一个已发布版本)以来累积的所有内容一次发布:含原 0.7 / 0.8 批次 + 第三波(RE2/shadcn/bun)+ 第四波「集众家之所长」+ SkillsMP 源 + GUI 各屏 shadcn 迁移。
July 4, 2026
verified-bot-commit-rs
Version updated for https://github.com/siiway/verified_bot_commit to version v0.2.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/siiway/verified_bot_commit/compare/v0.1.1...v0.2.0
July 4, 2026
Muninn Security Scanner
Version updated for https://github.com/skaldlab/muninn to version v0.3.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog [0.3.4] - 2026-07-04 Changed Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep 1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift). [0.3.3] - 2026-06-17 Changed Trivy default severity is now all levels (UNKNOWN through CRITICAL) instead of CRITICAL and HIGH only. osv-scanner and trivy now overlap on medium/low advisories by default so cross-scanner dedup and Detected by work without extra config. Consumers can narrow the Trivy scan with scanners.trivy.severity; fail-on still controls which findings fail the run. [0.3.2] - 2026-06-16 Fixed Suppressions with tool and/or rule-id are now applied. Previously only id (path substring) and fingerprint matchers worked; tool+rule-id entries parsed from muninn.yml but silently no-op’d. [0.3.1] - 2026-06-16 Fixed Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (rule_id, meta, rules, blobshas) now populate title, rule, and file in PR comments instead of empty shells (File: :0, `Rule: ``) (#41). Actionlint PR comments: fall back to kind (e.g. expression) when rule.name is absent; omit empty Rule lines. Poutine injection findings: render injection_sources as formatted Sources instead of plain meta.details text. Changed PR comment layout: shared field helpers; non-dependency findings follow File → Rule → optional extras → description; single-scanner dependency findings use File instead of a redundant Source line. [0.3.0] - 2026-06-16 Added Cross-scanner deduplication by advisory id: findings that report the same CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a lockfile and Trivy from a container layer) are now collapsed into a single finding. The contributing scanners are recorded in a new detected_by field (surfaced in the JSON report, the PR comment’s “Detected by” line, and a detectedBy SARIF result property). A CVE is preferred over GHSA so the same vulnerability converges on one id across scanners (#27). Richer dependency finding rendering: aggregated dependency findings now appear under a neutral [dependency] heading (instead of a single scanner’s name) with Package, Advisory (including the shared CVE), Detected by, and a Sources list showing where each scanner observed it. A new sources field on the finding (per-scanner tool + file) backs the JSON report (#27). Fixed PR comment rendering: scanner descriptions are flattened to a single line and their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence can no longer swallow later findings and the footer into a code block. [0.2.0] - 2026-06-15 Supply-chain hardening for the scanner image and signed, verifiable releases (closes #30).
July 4, 2026
SFDX Run Tests
Version updated for https://github.com/svierk/sfdx-run-tests to version v0.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed await flow test results via flow get test polling Full Changelog: https://github.com/svierk/sfdx-run-tests/compare/v0.0.1...v0.0.2
July 4, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.85.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.2 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.2 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.2 GitHub Action:
July 4, 2026
PHP Scoper GitHub Action
Version updated for https://github.com/WPTechnix/action-php-scoper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 — Initial Release A GitHub Action that runs PHP-Scoper to prefix PHP namespaces, preventing dependency conflicts when distributing PHP code as PHARs, WordPress plugins, or Composer libraries.
Features Docker-based action built on humbugphp/php-scoper:0.18.19 with Composer 2 baked in Automatic dependency installation — runs composer install before scoping (configurable) 5 configurable inputs: working-directory, scoper-config, run-composer-install, composer-args, output-directory Graceful fallbacks when scoper.inc.php or composer.json are missing 2 outputs: output-path (absolute path to scoped files) and count-scoped (file count) Proper CI/CD annotations — uses ::error:: and ::warning:: for clear workflow logs Dependabot integration for automated Docker/Actions dependency updates What It Solves PHP distributable code (plugins, libraries, PHARs) often bundles third-party dependencies that can clash with the same dependencies loaded by the host application. This action automates PHP-Scoper’s namespace prefixing so every build produces isolated, conflict-free code.
July 4, 2026
WP POT Generator
Version updated for https://github.com/WPTechnix/wp-pot-generator to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 – Initial Release First public release of WP POT Generator, a GitHub Action for generating WordPress .pot translation files using WP-CLI inside a Docker container.
✨ Features Generate .pot files for WordPress plugins and themes Powered by wp i18n make-pot running in Docker Automatic detection of plugin/theme slug Automatic detection of the text domain Support for the <slug> placeholder in custom output paths 10 configurable inputs for flexible generation 4 action outputs for use in GitHub Actions workflows Validation and clear GitHub Actions log annotations for improved error reporting 🧪 Quality Comprehensive test suite covering plugins, themes, custom configurations, include/exclude patterns, and source subdirectories CI pipeline with schema validation, ShellCheck, actionlint, and end-to-end tests Dependabot configuration for GitHub Actions and Docker dependencies Conventional Commit enforcement with Commitlint 🚀 Quick Start - name: Generate POT file uses: WPTechnix/wp-pot-generator@v1 See the README for full documentation and configuration examples.
July 4, 2026
AI-Driven ADR Enforcer
Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.5...v1.1.6
July 4, 2026
Powderworks Housekeeping
Version updated for https://github.com/zmaril/housekeeping to version v1.6.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Multi-language coverage: ci-exists demands test+lint+fmt per detected language (rust, js, python, ruby, go); ruby joins ecosystem detection; new builds check (every build target runs in CI, tauri heavy-target rules) and codegen-drift check ([[codegen]]-declared regen commands must run + zero-diff in CI). v1 fast-forwarded.
July 4, 2026
Setup poly CLI
Version updated for https://github.com/Goldziher/polylint to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Colored poly hooks install / uninstall output — a green ✓ header with the hook count and the (relative) hooks directory, then one line per hook name, replacing the flat list of absolute paths. Changed Installed git-hook shims resolve poly from PATH rather than baking in an absolute path to the binary, so a hook always runs whatever poly is current (a recorded absolute path could pin a stale or moved build). When poly is not on PATH the shim now fails with a clear, actionable message and a non-zero exit instead of proceeding as though the hook had passed. Re-run poly hooks install to migrate existing shims. Fixed Native-toolchain formatter output is normalized to LF line endings; some first-party CLIs emit CRLF on Windows, which made output platform-dependent.
July 4, 2026
Vizb Action
Version updated for https://github.com/goptics/vizb to version v0.14.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(ci): replace artifact storage with R2 in stateful CI example by @fahimfaisaal in https://github.com/goptics/vizb/pull/180 fix(merge): replace only colliding tag data on same-tag merge by @fahimfaisaal in https://github.com/goptics/vizb/pull/181 fix(merge): ensure tag-axis dimension is present in axes by @fahimfaisaal in https://github.com/goptics/vizb/pull/182 docs(merge): document same-tag replacement and auto-axis behavior by @fahimfaisaal in https://github.com/goptics/vizb/pull/183 Full Changelog: https://github.com/goptics/vizb/compare/v0.14.0...v0.14.1
July 4, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.379.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/30cfc3007d8b9e711c803695d20105735964ad29 with plugin-scanner 2.0.979.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.378...v1.2.379
July 4, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.379.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.379
July 4, 2026
PHP Obfuscator
Version updated for https://github.com/iSerter/php-obfuscator to version v0.1.7.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.7 (2026-07-04) Bug Fixes resolve named-argument label scrambling for non-obfuscated code (3646805) Miscellaneous Chores update php-obfuscator version in README to 0.1.7 (b06bed8)
July 4, 2026
ShipSignal readiness gate
Version updated for https://github.com/jpaul67/ShipSignal to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Release cadence & lead time from tags (Package K) — tags-per-month, median inter-tag gap, and median lead time from commit to release tag, derived entirely from git tags. Filters to release-shaped tags (overridable via .shipsignal.toml’s release_tag_pattern). Context only, never scored — tags aren’t deploys. Outcomes: revert pairs & time-to-correction (Package J) — median time-to-correction from matched revert pairs, plus the change-failure proxy relabeled and rendered alongside it. Context only, never scored. .shipsignal.toml config file (Package G) — repo-local defaults for AI aliases, squash detection, release-tag pattern, readiness thresholds, and badge label, picked up automatically by every command. Full details: CHANGELOG.md
July 4, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.81.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.81.1 (2026-07-04) Bug Fixes (landing): prerender homepage so crawlers see content (was ssr=false → empty shell) (cfa704e)
July 4, 2026
spek - OpenSpec Static Site
Version updated for https://github.com/kewang/spek to version v1.3.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fix: the IntelliJ plugin now installs on IntelliJ Platform 2026.1 (build 261.x) and newer — the until-build upper bound (253.*) that caused “requires IDE build 253.* or earlier” has been removed, so the plugin tracks current and future IDE releases (#4) Update the published kewang/spek GitHub Action off the deprecated Node 20 runtime — bump actions/checkout to v7, actions/setup-node to v6, and actions/cache to v6; internal CI workflows and README examples updated to match (#7)
July 4, 2026
Setup runner cli
Version updated for https://github.com/kjanat/runner to version v0.16.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed npx runner-run now resolves to the full CLI. Added a runner-run bin alias; previously npx failed with could not determine executable to run because neither shipped bin (run, runner) matched the package name. (Reaches users only on this published release; npx runner-run@0.16.0 stays broken.) The no-prebuilt-binary error now names the bun minimumReleaseAge pitfall: its age gate also filters the @runner-run/* platform packages, which must be excluded by exact name (no scope/glob), not just the runner-run facade. Changed Internal: the run alias binary now dispatches through the same dispatch entry point as runner, building a typed Cli from the parsed alias rather than keeping a second resolver-override and command-dispatch copy in dispatch_run_alias. The alias keeps its bespoke help/version forwarding, flat completions, and run man page. One behavior delta: a bare run -k/-K (a chain-failure flag with no task and no -s/-p) now maps to the project dashboard (command: None) and drops the inert chain-failure flag before resolving overrides, so it no longer errors when the opposite polarity is supplied out-of-band via RUNNER_KILL_ON_FAIL/RUNNER_KEEP_GOING or a [chain] config. The old eager builder kept the flag and hit the cross-source conflict; the dashboard never consults the failure policy, so dropping it is correct. See https://github.com/kjanat/runner/issues/52. What’s Changed refactor(run): unify run alias dispatch; do not remove RunAliasCli by @kjanat in https://github.com/kjanat/runner/pull/72 Full Changelog: https://github.com/kjanat/runner/compare/v0.16.0...v0.16.1
July 4, 2026
Clausura Code Review
Version updated for https://github.com/liuyanghejerry/Clausura to version v1.0.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/liuyanghejerry/Clausura/compare/v1.0.7...v1.0.8
July 4, 2026
ReviewGate
Version updated for https://github.com/LVTD-LLC/reviewgate to version v0.1.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Action] Simplify ReviewGate configuration by @rasulkireev in https://github.com/LVTD-LLC/reviewgate/pull/28 Full Changelog: https://github.com/LVTD-LLC/reviewgate/compare/v0...v0.1.10
July 4, 2026
Setup Raven
Version updated for https://github.com/martian56/setup-raven to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installs the Raven toolchain (raven, rvpm) on Linux and Windows runners from the Raven GitHub releases and caches the rvpm package cache between runs.
raven-version input: a release like 2.22.0, or latest (the default) cache input: caches ~/.rvpm/cache keyed on the repository’s rv.toml files raven-version output: the tag that was installed Use it with:
July 4, 2026
hestia-cache
Version updated for https://github.com/Mic92/hestia to version v2.0.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Usage - uses: Mic92/hestia@v2.0.0 with: version: v2.0.0 ⚠️ New cache format — one-time reset v2 introduces a new on-disk cache format, so existing cache entries from v1 will not be reused. The first runs after upgrading repopulate the cache from scratch; old data ages out automatically via GC. No action is required.
July 4, 2026
Miso PR Review
Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: dead-code removal and dedup sweep by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/366 fix(forgejo): structured gh api for GitHub comments, unified sticky-comment selection by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/376 refactor(classifier): declarative rule tables for pr_kind and risk flags by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/377 fix(security): derive fork-ness once, fail closed on degraded PR metadata by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/380 fix(precheck): read prior-review metadata via JSON side-file, drop eval by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/378 refactor(ci-gate): normalize external checks once in the platform seam by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/379 test(redact): comprehensive secret-redaction coverage by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/381 docs(verdict): pin the bash/Python verdict-turn contract with equivalence tests by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/385 refactor(enrichment): extract run_enrichment core into pr_reviewer modules by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/386 ci: enforce pytest coverage gate (baseline 76%, gate 72%) by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/382 test(forgejo): unit-test _diff_positions in isolation by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/383 test(env): hard gate on cross-block env binding drift in action.yml by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/384 fix(platform): resolve platform once in the precheck; PLATFORM-aware _is_forgejo_mode by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/387 fix(mcp): correct tool-name docs, log loop outcome, resolve separator aliases by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/390 refactor(utils): consolidate env_int, DeadlineBudget, and compare summarization by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/391 ci(github-action): update action misospace/pr-reviewer-action (v2.0.0 → v2.0.5) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/392 docs(agents): replace stale saffron-lane label table with ad-hoc agent/ convention by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/393 docs(release): document versioning policy; keep pre-releases off the floating major tag by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/394 perf(native-loop): dedup verdict-turn corpus sections; collapse skipped-source boilerplate by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/395 refactor(review): unify primary/fallback/smart model calls behind call_model_tier by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/396 perf(context): parallelize advisory phases, fan out enrichment API calls, collapse repo-impact scans by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/397 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.0.5...v2.1.0
July 4, 2026
Nox Security Scanner
Version updated for https://github.com/Nox-HQ/nox to version v1.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.4.2 (2026-07-04T12:58:01Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Bug Fixes cf5037c61c7b201a8a53976c0c05096aa089a380 fix(discovery): honor .gitignore when scanning from a git worktree (#140) (#141) Others 2ea7b7ffd9f8ab7ff6cc57842bca1cbe9589edd1 chore(deps): bump golang.org/x/net from 0.48.0 to 0.55.0 in /plugins/nox-plugin-reachability (#138) fb2e6cdd8aa6ee8adc20162aa6436d885ece0ff5 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-red-team (#139) Full Changelog: https://github.com/nox-hq/nox/compare/v1.4.1...v1.4.2
July 4, 2026
Changelog Bot Runner Nyaomaru
Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed refactor: simplify changelog run and why utilities by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/151 test: type changelog run mocks by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/152 Release: 0.6.3 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/153 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.3
July 4, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.25.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection/secret precision (ruleset 26): two FPs on a real popular project (infiniflow/ragflow) closed, recall-preserving. (1) Prompt-injection phrases held in C-family value-strings — a security tool’s own pattern table (Description: "prompt injection: ignore previous instructions", "DAN (Do Anything Now) …" in a Go file) — no longer flag ST-PROMPT-INJECTION. A new code_context policy strings_and_comments_all demotes matches inside Go/JS/TS/Rust/… string literals (new IndexedFile.in_c_string machinery), opted into only by ST-PROMPT-INJECTION; every other rule still treats a credential path in a C-family string as real access. (2) A commented-out secret in a Python comment (# OAuthConfig(client_secret="…")) no longer flags ST-SECRET-EMBEDDED — the rule now uses code_context="comments". Recall preserved: a live injection in an instruction surface / prose and a real embedded secret in code still fire. New unit tests + a benign fp_go_pattern_defs fixture; FP floor and efficacy (100%/100%) stay green.
July 4, 2026
Python Semantic Release - Publish
Version updated for https://github.com/python-semantic-release/publish-action to version v10.6.0.
This action is used across all versions by 660 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v10.6.0 (2026-07-04) Build System deps: Bump python-semantic-release from v10.5.3 to v10.6.0 (#101, 4f3c5d7) Detailed Changes: v10.5.3…v10.6.0
July 4, 2026
Quant Agent Tools
Version updated for https://github.com/quantcdn/quant-cloud-agent-tools-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: send edgeFunctionCode per the v3 custom-tools contract (422 on every run) by @steveworley in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17 chore(deps-dev): bump @types/node from 20.19.35 to 25.9.1 by @dependabot[bot] in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16 New Contributors @steveworley made their first contribution in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17 @dependabot[bot] made their first contribution in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16 Full Changelog: https://github.com/quantcdn/quant-cloud-agent-tools-action/compare/v1...v1.1.0
July 4, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.14.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.14.1 Released 2026-07-04.
Security and hygiene patch.
Security Log injection: user-controlled values (task ids, roles, session ids, reasons, branches, and git output) are sanitized before they reach a log entry across the task-server routes, task store, spawner, orchestrator, and retrospective paths, so a crafted value can no longer forge log lines. Task-failure/reopen/cancel/block reasons are additionally CR/LF-stripped and length-capped at the request boundary. Sensitive-data logging: the openai_agents adapter and runner no longer log request headers, body, or the resolved API key value; only the env var name is recorded. Fixes The qwen adapter passes --approval-mode yolo, the current documented qwen-code auto-approve flag, clearing the adapter contract drift. (#2197) Internal Restored the integration-test harness (server auth disabled in the fixture, all role templates created, merge-preflight guards satisfied) so the end-to-end orchestration tests pass again. (#2205) Resolved refurb idiom findings across the routes, cost, agents, and orchestration modules.
July 4, 2026
Validate Syscribe Model
Version updated for https://github.com/sjames/syscribe to version v0.30.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(find): avoid panic when doc-body cap lands mid-UTF-8-char by @sjames in https://github.com/sjames/syscribe/pull/80 fix(matrix): render covered-but-failing requirement as ▣, not ✗ by @sjames in https://github.com/sjames/syscribe/pull/81 feat(scan): LLM-scale corpus scanning — Tiers A/B/C (stats, digest, search-text, summarize, topics, clusters) by @sjames in https://github.com/sjames/syscribe/pull/82 feat: displayOrder field + W047 unrecognized-field warning by @sjames in https://github.com/sjames/syscribe/pull/83 Full Changelog: https://github.com/sjames/syscribe/compare/v0...v0.30.0
July 4, 2026
UUAID Init — give your repos agent a permanent identity
Version updated for https://github.com/uuaid/init-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uuaid-init v1 — mint a permanent agent identity + trust badge in one CI step.
July 4, 2026
VAPT Insights Security Scan
Version updated for https://github.com/vaptinsights/security-scan-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed VAPT Insights Security Scan v1.0.0 Initial GitHub Marketplace release of the VAPT Insights Security Scan Action.
Features Generates CycloneDX SBOMs using Trivy Uploads SBOM results securely to VAPT Insights Supports complete repository scans Supports nested application folders Supports matrix-based monorepo service scanning Uses commit SHA values for artifact versioning Supports custom artifact names and versions Usage - name: Run VAPT Insights Security Scan uses: vaptinsights/security-scan-action@v1 with: api-key: ${{ secrets.VAPT_INSIGHTS_API_KEY }} scan-path: . artifact-name: ${{ github.event.repository.name }}
July 4, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.704.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.704.1 Released 2026-07-04
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.703.7, interleaved on one runner against the pinned corpus (157 metrics compared).
July 4, 2026
Powderworks Housekeeping
Version updated for https://github.com/zmaril/housekeeping to version v1.4.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Captain dispatch: housekeeper captain --dispatch (action input dispatch: true) triggers every member’s self-audit immediately — new checks reach the fleet on demand, not a week of crons later; workflow_dispatch joins the required member triggers. Unknown keys are surfaced at both scales: [policy.*] typos fail the captain, .housekeeping.toml typos fail the audit. v1 fast-forwarded.
July 4, 2026
Send Email with MailKite
Version updated for https://github.com/mailkite/send-email-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Send email with MailKite from any workflow. See README for inputs + the inbound→repository_dispatch recipe.
July 4, 2026
Quorum consensus security scan
Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.8.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog bf624853a310007127d7223e7f1c1952186b028f: Merge pull request #60 from Martinez1991/feat/action-advice-inputs (@Martinez1991) 1723f878b86eaab1925a57820f79ce9160b8ee96: feat(action): expose the advisory layer (–advice / AI / –fix) as inputs (@Martinez1991)
July 4, 2026
Docker Swarm Deployment Action
Version updated for https://github.com/matchory/docker-swarm-deployment-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: re-enable YAML merge keys dropped by js-yaml v5 by @Radiergummi in https://github.com/matchory/docker-swarm-deployment-action/pull/152 feat: active Compose → Swarm reconciliation by @Radiergummi in https://github.com/matchory/docker-swarm-deployment-action/pull/153 Full Changelog: https://github.com/matchory/docker-swarm-deployment-action/compare/v1.1...v1.2.0
July 4, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v5.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [5.5.0] — 2026-07-03 Added Runtime framework-root detection (_detect_framework_root) — auto-detects framework/library repos from package metadata, enabling noise suppression on arbitrary cloned repos (not just known benchmark paths) Test-file noise policy (_is_test_file, _TEST_FILE_NOISE_RULES) — suppresses CWE-798/327/338 findings in test fixtures, examples, and demos Expanded framework-internal path markers — 60+ new patterns covering cloned campaign repos (py-flask/, js-express/, etc.) and installed packages Confidence downgrading for non-exempt framework-internal findings (0.5 cap) and test-file findings (0.6 cap) Changed rich moved to production dependencies — declared explicitly in pyproject.toml; guardrails updated to 10MB limit with rich allowlist CWE-617 severity: high → medium (error-handling, not direct exploit) CWE-532 severity: high → medium (information leak) README precision claims — replaced “0.4% FP rate” with honest “36-58% precision on web apps” Test count badge: 1,207 → 1,234 Fixed Framework noise suppression now works on cloned repos — previously only matched specific benchmark directory names; now catches py-flask/, js-express/, and 30+ common clone patterns FrameworkFingerprint made mutable — inspect_ast_node() and verify_endpoint_protection() can now set detected_framework at runtime verify_endpoint_protection checks default values — FastAPI = Depends(...) pattern (default value, not annotation) now detected Engineering Spec Compliance Phase 1.3: Dependency declaration (rich as prod dep) Phase 1.4: mypy --strict added to CI Phase 2.2: register_symbol, resolve_call, propagate_taint_cross_file in interprocedural.py Phase 2.3: FrameworkFingerprint.inspect_ast_node + verify_endpoint_protection Phase 2.4: Rule severity recalibration Phase 3.1: generate_remediation_snippet with 6 code-fix templates Phase 3.4: ProcessPoolExecutor parallel analysis Phase 3.5: safe_parse_target with 3-encoding fallback Phase 4.1: docs/rules/index.md rule catalog Phase 4.2: rules/custom_checks.yaml blueprint Phase 4.3: filter_findings_by_git_diff PR isolation
July 4, 2026
Synaptic PR Review
Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.2.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.2.7 Fix: summary comment now updates in-place on re-review instead of duplicating (post_inline.py) Fix: new delete_issue_comment() helper for cleaning up stale OpenCode-created comments ( eview_context.py)
July 4, 2026
ModelBound Skill Check
Version updated for https://github.com/ModelBound/skill-check-action to version v1.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Action that lints, trust-scores, and estimates token savings for agent skill files on every pull request via ModelBound.co context management tools.
July 4, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.7.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.7
Fix Resolving Class Names Shadowed By Local Variables
July 4, 2026
PatchFlow Security Scan
Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PatchFlow CLI v0.1.3 Benchmark Results (v1.0) 18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories 5 historical CVE repos: 100% recall, 387K LOC 10 clean repos: 0.094 HC/KLOC, 720K LOC See Benchmark Report v1.0 for details.
July 4, 2026
Setup xdrun
Version updated for https://github.com/phillarmonic/setup-drun to version v2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Drun v2
July 4, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The lookup tools now attribute the calling agent — and the release pipeline publishes the MCP-registry listing automatically.
Client identity on lookups (#91): check_server, list_servers, and request_grade send the connected client’s handshake identity (name/version plus declared title, website, description, and capability keys such as sampling/roots) to polygraph.so’s aggregate per-agent usage counters. Software metadata only — nothing about the user is read or sent; all fields are optional server-side. Official MCP Registry auto-publish (#93): pushing a litmus-v* tag now also publishes server.json to registry.modelcontextprotocol.io via GitHub OIDC, with a fail-fast version-drift check. polygraph plugin 0.6.0: spawn pinned to this release (#92). No grading-semantics changes: litmus-v12 / litmus-skill-v2 unchanged.
July 4, 2026
Generate Roq Site
Version updated for https://github.com/quarkiverse/quarkus-roq to version 2.1.5.
This action is used across all versions by 75 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Enhance Liquid-to-Qute converter for full Jekyll migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/978 Fix capture blocks in Jekyll converter blocks by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/982 Expand on how to use bundled sass output by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/984 Fix aliases to work with and without trailing slash by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/995 No co-authored by any LLM in commits. by @jtama in https://github.com/quarkiverse/quarkus-roq/pull/1000 Fix svg diagram rendering by @jtama in https://github.com/quarkiverse/quarkus-roq/pull/997 added code block menu language dropdown by @edewit in https://github.com/quarkiverse/quarkus-roq/pull/994 improved navigation by @edewit in https://github.com/quarkiverse/quarkus-roq/pull/990 Add tips on sanisation for Jekyll migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/983 Add utilities for converting Jekyll frontmatter to Roq equivalents by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/998 Hook migration into top-level build and parent by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1004 Bump info.picocli:picocli from 4.7.5 to 4.7.7 by @dependabot[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1010 Trivial formatting - tidy missing line break in root pom by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1012 docs: custom search trigger section to Lunr Search documentation by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1016 ci: Update action versions for Java setup and GitHub Pages configuration by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1015 Add tests specifically checking slug overrides are honoured by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1008 Add minimum Quarkus version requirement to release notes by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1014 Bump org.mvnpm.at.fortawesome:fontawesome-free from 7.2.0 to 7.3.0 by @dependabot[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1017 fix: Enhance image handling for absolute paths in Page model by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1024 fix: handle null collections in getPosts method by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1023 Allow link defaults to be configured globally by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1020 Support deeply nested data directories as grouped CDI beans by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1011 Add list:whereExp filter for Jekyll where_exp migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1021 Evaluate (sort of) conditional directives in asciidoc before yupiik header parsing by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1003 docs: enhance SEO documentation with per-page meta tag configuration by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1025 Honour slug in frontmatter with sneaky path conditional by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1028 docs: add holly-cummins as a contributor for code by @allcontributors[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1032 docs: add myfear as a contributor for code by @allcontributors[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1031 Add :dir placeholder to support slug overrides and nested paths by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1013 Add dir segment placeholders by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1027 Add quarkus-roq-plugin-og-image extension by @myfear in https://github.com/quarkiverse/quarkus-roq/pull/1007 Update Jekyll frontmatter converter for pagination and permalink migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1039 Add linktree theme by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1043 Consistency em FlatMap in review jerome by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1038 Revert og-card plugin to unblock release by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1046 Fix theme:base codestart using default theme content by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1047 Jekyll migration: Add converter to transform _config.yml by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/991 Add medium-zoom for image zoom support by @mcruzdev in https://github.com/quarkiverse/quarkus-roq/pull/910 Introduce hybrid mode as a plugin by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1019 Add qute: false alias, CLI –version, alert styling, and collapsible sections by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1048 Bump current version to 2.1.5 by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1049 New Contributors @myfear made their first contribution in https://github.com/quarkiverse/quarkus-roq/pull/1007 Full Changelog: https://github.com/quarkiverse/quarkus-roq/compare/2.1.4...2.1.5
July 4, 2026
PR Explainer AI
Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Understanding is the new bottleneck Generates architectural background and change intuition from the PR diff Builds HTML flow diagrams and a code walkthrough Includes a 5-question interactive quiz for review comprehension Supports OpenRouter with configurable model selection Defaults to deepseek/deepseek-v4-flash How it works:
July 4, 2026
dotenv Seeder
Version updated for https://github.com/scrlkx/dotenv-seeder to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/scrlkx/dotenv-seeder/compare/v1...v2
July 4, 2026
ShipGate-ai
Version updated for https://github.com/ShipGate-ai/ShipGate to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed a bug which restricted allowlisted repos to be not processed as well.
July 4, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.14.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.14.0 Released 2026-07-04.
Multi-provider orchestration hardening. A large batch of correctness and run-safety fixes for real-codebase runs across mixed providers (Claude, OpenAI, OpenRouter, DeepSeek, MiniMax, Qwen, Gemini), contributed by @shanemmattner and finished to green.
Fixes Stalled-manager watchdog no longer misdiagnoses a healthy manager as an auth failure: a manager doing real root-cause investigation before it POSTs its first child task is no longer killed at a hardcoded deadline, the config override is honored, and the failure record names the real cause. (#2179) Failure classifier stops false-positive-killing healthy workers: bare-substring patterns (413, 429, 401, max_tokens, context window) no longer match structured tool-call log data; detection is anchored to real error shapes. (#2183) Janitor acceptance checks tolerate idiomatic worker paths: path_exists honors explicit globs and an opt-in fuzzy basename fallback, so a run where workers placed correct output at repo-idiomatic paths is not cascaded to a false sev1. (#2186) Injected .claude/skills/bernstein-*.md files are excluded from work-branch commits, so they stop causing a merge conflict on every worker merge. (#2187) Per-call token usage is priced and surfaced on the openai_agents provider path, so budget guards are no longer inert on non-Claude runs. Model pricing matches the most specific key first, so mini and flash variants price at their own rate instead of the parent model rate. strict_json_schema is disabled for non-OpenAI models that reject it, with diagnostic logging. Plus the rest of the 22-fix batch across adapters, tasks, cost, routing, quality, and observability. Features Tunable agent run-length limits: max_turns, an error-budget floor, and max_agent_runtime_s, configurable per run. Internal Pricing table extracted into a dependency-free cost.model_prices leaf so adapters can price a call without reaching scheduler internals; public create_pr API preserved; a diagnostic pre-call log that dumped request headers/body verbatim is now redacted.
July 4, 2026
Docker swarm stack deploy
Version updated for https://github.com/spawnlab-dev/stack-deploy-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed hotfix: deps update and CVE fixes by @pradeepbbl in https://github.com/spawnlab-dev/stack-deploy-action/pull/27 Full Changelog: https://github.com/spawnlab-dev/stack-deploy-action/compare/v1...v1.0.2
July 4, 2026
MS Teams Notification (Adaptive Card)
Version updated for https://github.com/stackdone/ms-teams-notification to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed update (#1) (c033c3d) . (75037b1) fix (ab3960a) add . (2a8c9d9) Initial commit (15c66f4)
July 4, 2026
overllm
Version updated for https://github.com/theadamdanielsson/overllm to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Two deterministic model-hygiene rules.
deprecated-model: flags a model id that’s retired (the call 404s) or deprecated and scheduled for removal, and names the current model to switch to. Exact-match against a known list, so a live model or alias is never flagged. unsupported-params: flags temperature/top_p/top_k set on a model that rejects them — the OpenAI o-series and the newest Anthropic models, where the parameter is a no-op or a 400. Both stay silent when the model isn’t a plain string literal.
July 4, 2026
Expand AWS IAM Wildcards
Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.2.7.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/95 deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/94 check in codeQL config and workflow by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/98 deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/97 ci: bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/96 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/99 deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/101 ci: bump codecov/codecov-action from 6.0.0 to 6.0.1 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/100 ci: bump github/codeql-action from 4.35.3 to 4.36.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/102 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/103 deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/104 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/105 deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/108 ci: bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/107 ci: bump github/codeql-action from 4.36.0 to 4.36.2 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/109 ci: bump codecov/codecov-action from 6.0.1 to 7.0.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/106 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/110 deps: bump the npm-dependencies group with 4 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/111 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/112 fix release workflow sequencing by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/113 ci: bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/114 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/115 make release orchestration deterministic by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/116 Document release preflight checks by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/117 add 0th cut of release shell script by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/118 prep for v1.2.7 by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/119 reset versions to re-test release script by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/120 Prepare v1.2.7 release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/121 Full Changelog: https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.2.7
July 4, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.85.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.1 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.1 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.1 GitHub Action:
July 4, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.17.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.2 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/33 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.1...v0.17.2
July 4, 2026
spaces checkout run
Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.2 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/27 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.1...v0.17.2
July 4, 2026
Move Closed Issue to Top of Project Column
Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.19.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: wozaki/project-closed-issue-move-to-top-action@0636114292c9298d48a87622a2e25e5636ebe6d5 # v1.19.0 What’s Changed chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/147 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/148 Full Changelog: https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.18.0...v1.19.0
July 4, 2026
Setup Modern C++ Development Environment
Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix fatal error
July 4, 2026
Powderworks Housekeeping
Version updated for https://github.com/zmaril/housekeeping to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Marketplace-valid action metadata: display name “Powderworks Housekeeping”, description under 125 characters. The uses: zmaril/housekeeping@v1 interface is unchanged.
July 3, 2026
Setup Smurf
Version updated for https://github.com/clouddrove/smurf to version v1.1.5.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.1.5 (2026-07-03) Build deps: bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml deps: bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (#432) deps: bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml deps: bump actions/cache from 5 to 6 deps: bump msgpack deps: bump github.com/containerd/containerd deps: bump actions/checkout from 6 to 7 deps: bump github.com/Azure/azure-sdk-for-go/sdk/azidentity deps: bump k8s.io/apimachinery from 0.36.1 to 0.36.2 deps: bump the pip group across 1 directory with 2 updates deps: bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (#426) Fix add pod logs before pod down fix deployment validation for completed Kubernetes Job pods (#430) selm: update smurf selm log structure for failure pod Pull Requests Merge pull request #438 from clouddrove/fix/selm-logs Merge pull request #437 from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-f6ef7e54f3a1f4e2a05a66ed1a8702c07ae94346 Merge pull request #436 from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-5a15692ae38a05cc3aa3b7ab6744add91e9b8591 Merge pull request #433 from clouddrove/dependabot/go_modules/go_modules-6e0011ac6e Merge pull request #434 from clouddrove/dependabot/pip/docs/sm/docs/pip-b15cf8365f Merge pull request #435 from clouddrove/dependabot/github_actions/actions/cache-6 Merge pull request #431 from clouddrove/dependabot/github_actions/actions/checkout-7 Merge pull request #428 from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.36.2 Merge pull request #429 from clouddrove/dependabot/go_modules/github.com/Azure/azure-sdk-for-go/sdk/azidentity-1.14.0 Merge pull request #427 from clouddrove/dependabot/pip/docs/sm/docs/pip-cdb1555457
July 3, 2026
Devr Codeguard
Version updated for https://github.com/devr-tools/codeguard to version v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.8.1 (2026-07-03) Bug Fixes release: disable PyPI attestations for reusable-workflow publish (28a147d)
July 3, 2026
FacturaScripts Playground PR Preview
Version updated for https://github.com/erseco/action-facturascripts-playground-pr-preview to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new since v1.0.0 feat: append-to-description publish mode + workflow_run/pr-number support (#13) feat: warn (advisory, non-blocking) when the preview URL risks HTTP 414, and document the mitigation in the README (#19) ci: verify-dist gate, dependabot-dist auto-rebuild, immutable-action publishing Various dependency bumps All changes are backward compatible: new inputs default to the previous behavior, and the URL-length check only warns, it never fails the action. No breaking changes, so the v1 tag is being moved to this release rather than cutting a v2.
July 3, 2026
Garnet Runtime Visibility
Version updated for https://github.com/garnet-org/action to version v2.1.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 111 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in https://github.com/garnet-org/action/pull/81 fix: improve error messages by @nicolasparada in https://github.com/garnet-org/action/pull/84 feat: add agents.md to repo by @nicolasparada in https://github.com/garnet-org/action/pull/85 Full Changelog: https://github.com/garnet-org/action/compare/v2.1.0...v2.1.1
July 3, 2026
ghcr-manager
Version updated for https://github.com/ghcr-manager/ghcr-manager to version v1.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/ghcr-manager/ghcr-manager/compare/v1.1.4...v1.1.5
July 3, 2026
Easy Npm Publish
Version updated for https://github.com/glitch452/easy-npm-publish to version v1.0.43.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Chores deps: update all non-major dependencies (595d091)
July 3, 2026
GitHub Action for GraalVM
Version updated for https://github.com/graalvm/setup-graalvm to version v1.6.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4,081 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the “all” group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/graalvm/setup-graalvm/pull/222 Add support for GraalVM innovation releases by @fniephaus in https://github.com/graalvm/setup-graalvm/pull/223 Full Changelog: https://github.com/graalvm/setup-graalvm/compare/v1.5.6...v1.6.0
July 3, 2026
L10n.dev AI Localization Automation
Version updated for https://github.com/l10n-dev/ai-l10n to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: add GlossaryManager and LinguisticInstructionsManager and CLI for them by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/48 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.8.0...v1.9.0
July 3, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.0 The normalized-findings major (ADR-030). The kit now correlates the scanner evidence it already composes — six kit evidence JSONs plus four external SARIF drops — into one deduplicated, KEV/EPSS-ranked finding view, delivered as a new versioned artifact and a new command. Stateless by design: one clone-only run, no database, no state between runs, no network.
July 3, 2026
Run Maester
Version updated for https://github.com/maester365/maester-action to version v1.2.0.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci: bump actions/checkout from 6 to 7 in the all-actions group by @dependabot[bot] in https://github.com/maester365/maester-action/pull/43 Interactive report available as GitHub artifact with a direct link by @svrooij in https://github.com/maester365/maester-action/pull/42 Full Changelog: https://github.com/maester365/maester-action/compare/v1.1.0...v1.2.0
July 3, 2026
Quorum consensus security scan
Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 8b28bef427d98b63b5f50a96aaf0fbc1e4575894: Merge pull request #45 from Martinez1991/feat/crosswalk-multicloud-azure-gcp (@Martinez1991) 8852a90f27d4d886188266d468c6962b3e31f789: feat(crosswalk): multi-cloud consensus — Azure + GCP + more AWS (real overlaps) (@Martinez1991)
July 3, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.12.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.12 (2026-07-03)
July 3, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.6
Treat NUL Bytes As Ignorable Whitespace
Type Schema.SObjectType Describe-Result Properties As Their Real Types
Resolve Null-Argument Constructor Overloads By Most-Specific Non-Null Position
Allow Public Override Of A Global Abstract Method
July 3, 2026
SpringSentinel
Version updated for https://github.com/pagano-antonio/springsentinel-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Create README.md (3e1d589) Update test.yml (3a7ed11) Update entrypoint.sh (4e15ea0) Update entrypoint.sh (6418942) Update entrypoint.sh (51f3a42) Create test.yml (d46361f) Create entrypoint.sh (bcf8584) Create Dockerfile (72d2f0b) Create action.yml (89fad1e)
July 3, 2026
Rust Lint Action
Version updated for https://github.com/Profiidev/rust-lint-action to version v4.3.0.
This action is used across all versions by 25 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Lint action version v4.3.0 has been released!
What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/25 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/26 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/27 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/28 chore(deps): pin dependencies by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/29 chore(deps): update actions/checkout digest to df4cb1c by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/30 chore: shared renovate config by @Profiidev in https://github.com/Profiidev/rust-lint-action/pull/31 fix: add warnings on linter success by @Profiidev in https://github.com/Profiidev/rust-lint-action/pull/32 Release version v4.3.0 by @profidev-commit-bot[bot] in https://github.com/Profiidev/rust-lint-action/pull/33 Full Changelog: https://github.com/Profiidev/rust-lint-action/compare/v4.2.0...v4.3.0
July 3, 2026
goog - OG Image Generator
Version updated for https://github.com/riceball-tw/goog to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/riceball-tw/goog/commits/v1.0.0
July 3, 2026
DiffGate Review Triage
Version updated for https://github.com/srbsa/diffgate to version v0.7.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373) fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0) release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9) release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc) release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf) fix: action.yml name collision + description over Marketplace’s 125-char cap (05227d2) fix: shorten server.json description under the MCP registry’s 100-char cap (2a4ada1) release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6) release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd) docs: promote history-audit as the quick-start aha moment (2611797)
July 3, 2026
Groundskeeper Issue Triage
Version updated for https://github.com/theadamdanielsson/groundskeeper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release.
Groundskeeper is a first responder for new GitHub issues. When someone opens one, it reads your repo, then posts a single grounded comment: a duplicate check, the repro info that’s missing, a pointer to the relevant file and line, and suggested labels. If it doesn’t have anything solid to say, it stays silent.
July 3, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.84.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.84.1 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.84.1 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.84.1 GitHub Action:
July 3, 2026
Vibgrate Scan
Version updated for https://github.com/vibgrate/cli to version v2026.703.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.703.7 Released 2026-07-03
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.703.5, interleaved on one runner against the pinned corpus (157 metrics compared).
July 3, 2026
Setup vp
Version updated for https://github.com/voidzero-dev/setup-vp to version v1.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs: document the version release process by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/101 ci: auto-rebuild action bundle on Renovate dependency bumps by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/103 feat: resolve Vite+ version from package.json / catalog by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/102 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.13.0...v1.14.0
July 3, 2026
graph-sync
Version updated for https://github.com/wordlift/graph-sync to version v6.11.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wordlift/graph-sync/compare/v6.11.2...v6.11.3
July 3, 2026
backlog-to-pr
Version updated for https://github.com/wrbl606/backlog.md-to-pr to version 0.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.2...0.0.3
July 3, 2026
Setup Modern C++ Development Environment
Version updated for https://github.com/wx257osn2/cxx_environment to version v20260703.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump up base image to resolute outdated: clang-format 17-20 enabled gnucoreutils bump up many components: gcc: 15.2 -> 16.1 Boost: 1.89.0 -> 1.91.0 CMake: 4.1.1 -> 4.3.3 difftastic: 0.64 -> 0.69 mold: 2.40.4 -> 2.41.0 wild: 0.8.0 -> 0.9.0 removed components: old clang-format s clang-head $ ./pull.bash v20260703
July 3, 2026
AGENTS.md Lint (Schliff)
Version updated for https://github.com/Zandereins/schliff to version v8.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added operational_coverage dimension for AGENTS.md (#83). Measures whether an AGENTS.md actually equips a coding agent to operate the repo: real setup/build/test commands (command-family classification, doc-wide, headings never gate) plus code-style / gotchas / PR directive sections with concrete code tokens. Surfaced in the CLI dimension table, the GitHub Action’s PR comment, and accepted by the leaderboard submit API. Changed BREAKING (scores): the AGENTS.md headline profile is now structure 0.40 / operational_coverage 0.40 / efficiency 0.20 (was 0.5/0.5). efficiency was a validated gameable proxy — a junk-fence-stuffed doc scored 92.5/A while the same real commands written inline scored 70.0/C. All AGENTS.md scores re-baseline (30-file corpus: mean 61.06, no file reaches S). SKILL.md / CLAUDE.md / .cursorrules / system-prompt scoring is byte-identical to 8.3.0. Security Fixed a ReDoS in the operational_coverage heading regex (quadratic on whitespace-only heading lines) before it ever shipped — found by a 75-agent adversarial review pass, together with a directive-gate gaming hole, a fence-state desync, and 12 command-recall bugs. Full record: docs/specs/agents-md-operational-coverage.md §11. Full changelog: https://github.com/Zandereins/schliff/compare/v8.3.0...v8.4.0
July 3, 2026
GHCR Cleanup Manager
Version updated for https://github.com/ghcr-manager/ghcr-cleanup-manager to version v1.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.4...v1.1.5
July 3, 2026
SQL/NoSQL Syntax Validator
Version updated for https://github.com/GianfrancoArocutipa/sql-nosql-validator-action to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Primera versión del SQL/NoSQL Syntax Validator Action. Valida archivos .sql y .mongo sin servidor requerido.
July 3, 2026
Tenter Scan (Rust)
Version updated for https://github.com/goweft/tenter-rs to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/goweft/tenter-rs/compare/v2...v2.1.0
July 3, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.372.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/dae00cbd1175595edfdf44f1b84bc3f043d08a0b with plugin-scanner 2.0.972.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.371...v1.2.372
July 3, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.372.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.372
July 3, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.6.0 (2026-07-03) Install-time guard + GitLab-native output + registry hardening (both remaining roadmap bets)
Ships the last two strategic bets from the 2026-07 roadmap. A second 4-lens adversarial verification gate reviewed the diff and BLOCKED the first candidate with 5 confirmed findings, all fixed here (a real Windows RCE among them). 40 new tests (1120 total).
July 3, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.2.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.2.9
July 3, 2026
isreadyai — AI readiness audit
Version updated for https://github.com/isreadyai/audit-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release 🎉 Audit how AI crawlers (GPTBot, ClaudeBot, PerplexityBot) read your site - straight from your CI.
Highlights Deep-crawl audit of any URL, parsed exactly the way Al crawlers see it (no JS execution) 0-100 score + grade, with the full per-page report written to the GitHub job summary CI gate: the step fails when the score drops below your threshold Branch preview support: boot your environment with command, scan it locally before it ships Optional authenticated CI report + repo badge on isready.ai with a Pro/Team api-key (OIDC-verified) Zero setup: pre-bundled, dependency-free - no install step at runtime Usage - name: AI readiness audit uses: isreadyai/audit-action@v1 with: url: ${{ env.DEPLOY_URL }} threshold: 80 See the README for all inputs, outputs, permissions and security notes. Learn more at isready.ai.
July 3, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.7.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(shell): make setup-shell rc line self-healing when the CLI leaves $PATH by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/96 release: v1.7.1 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/97 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.7.0...v1.7.1
July 3, 2026
sops tools installer
Version updated for https://github.com/jkroepke/setup-sops to version v1.5.46.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): update dependencies by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/238 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.45...v1.5.46
July 3, 2026
ShipSignal readiness gate
Version updated for https://github.com/jpaul67/ShipSignal to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added README hero image + social-preview card GitHub Action: sticky PR comments (pr-comment input) — score, grade, top 3 fixes, kept updated in place; degrades safely on fork PRs Fixed Security hardening: argument-injection fix in gitinfo.clone, least-privilege GITHUB_TOKEN, all third-party Actions pinned to commit SHAs + Dependabot, secret scanning + branch protection enabled CI: full-history checkout fixes a PR-merge-commit misclassification in the self-scan dogfood tests Full details: CHANGELOG.md
July 3, 2026
probelock gate
Version updated for https://github.com/kelkalot/probelock to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add ingest pipeline and trace-mined probes by @kelkalot in https://github.com/kelkalot/probelock/pull/1 New Contributors @kelkalot made their first contribution in https://github.com/kelkalot/probelock/pull/1 Full Changelog: https://github.com/kelkalot/probelock/compare/v0.1.0...v0.2.0
July 3, 2026
Repository Languages and CodeQL Support Map
Version updated for https://github.com/lfventura/list-repository-languages to version v3.3.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: force_languages input by @lfventura in https://github.com/lfventura/list-repository-languages/pull/8 Full Changelog: https://github.com/lfventura/list-repository-languages/compare/v3.2.1...v3.3.0
July 3, 2026
MCIX Overlay Apply
Version updated for https://github.com/MettleCI/mcix-overlay-apply to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-overlay-apply/compare/v0.0.36...v0.0.37
July 3, 2026
MCIX System Version
Version updated for https://github.com/MettleCI/mcix-system-version to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-system-version/compare/v0.0.27...v0.0.37
July 3, 2026
MCIX Unit-Test Execute
Version updated for https://github.com/MettleCI/mcix-unit-test-execute to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-unit-test-execute/compare/v0.0.27...v0.0.37
July 3, 2026
hestia-cache
Version updated for https://github.com/Mic92/hestia to version v1.0.4.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Usage - uses: Mic92/hestia@v1.0.4 with: version: v1.0.4 What’s Changed gha: retry finalize when the uploaded entry is not yet visible by @Mic92 in https://github.com/Mic92/hestia/pull/86 Full Changelog: https://github.com/Mic92/hestia/compare/v1.0.3...v1.0.4
July 3, 2026
Agent Done Or Not
Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.10.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.10.1 — Marketplace branding + cleanup A packaging/metadata patch on top of v0.10.0. No engine behavior change — receipts, mode: verify, and the gates are identical.
What changed Marketplace branding on the composite Action (branding.icon: check-circle, color: green) so it can be listed on the GitHub Marketplace with an icon. Removed a now-unreachable inner mode != assert guard in the assert step (already gated by the step if: and the reject-unsupported-mode step). @v0 references in the docs now resolve via a moving v0 major tag that tracks the latest v0.x release. For the security-critical mode: verify gate, keep pinning an exact tag (e.g. @v0.10.1) as the README recommends. Verify quick reference - uses: actions/checkout@v4 # set up your runtime + deps here (setup-node, npm ci, …) - uses: mohamedzhioua/agent-done-or-not@v0.10.1 with: mode: verify checks: | test: npm test build: npm run build Full history in CHANGELOG.md.
July 3, 2026
Agent Security Harness
Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Promotes the funding-instrument checks that were a single dimension of the AP2 harness (AP2-015) into a first-class module — the tokenized card credential (Visa Trusted Agent Protocol / Mastercard Agentic Tokens) that sits inside an AP2 Payment Mandate as the instrument that actually moves money.
July 3, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.24.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Methodology litmus-v12 — two false-positive fixes so a server’s correct, defensive behavior is no longer graded as a fault.
C-04 (probe 3.2): a validation error that quotes the rejected input back (e.g. Pydantic input_value='…') is a safe rejection, not server-generated amplification — no longer a false D. (#85) C-02 (probe 2.1): a mutation verb under a negation (“Cannot create or revoke keys”) no longer reads as a permission-mislabel lie; clause-scoped, so a real “Deletes… Cannot be undone.” still trips. (#85) methodologyVersion moves litmus-v11 → litmus-v12 (a string, so older attestations coexist). Release bump in #86. Both fixes are covered by regression tests reproduced from real servers.
July 3, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.9.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.7.8 was tagged on the wrong commit and did not actually contain the enrichment fix; v1 pointer was updated but the deployed code path in fast-paths still skipped _enrich_candidate_licenses. This release ships the real fix: _enrich_candidate_licenses(candidates, target) is now called on the pin-arxiv and search-method fast-paths (gated on REMYX_LICENSE_GATE, idempotent, best-effort). REMYX-190 evidence: https://github.com/remyxai/VQASynth/issues/105 opened with license_class=unknown despite WnQinm/Annotator having a clearly readable BSD-3-Clause LICENSE — the fast-path never called the enrichment step.
July 3, 2026
DiffGate Review Triage
Version updated for https://github.com/srbsa/diffgate to version v0.7.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/srbsa/diffgate/compare/v0.7.6...v0.7.7
July 3, 2026
rag-redteam
Version updated for https://github.com/Srivatsa03/rag-redteam to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Adds embedding_inversion, a 7th probe that flags pipelines exposing raw embedding vectors (invertible back to source text per vec2text). Structural detector, a vulnerable/hardened demo pair, unit tests, and a threat-model section. Install or upgrade: pip install -U rag-redteam
July 3, 2026
Node Semantic Release
Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.193.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.193.0
1.193.0 (2026-07-03) ✨ Features remove is-first-release-tag (f210a51)
July 3, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.82.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.82.4 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.82.4 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.82.4 GitHub Action:
July 3, 2026
Setup Modern C++ Development Environment
Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed workaround for non-UTC timezone host environment Singularity/Apptainer binds Etc/UTC to host timezone at default speed up CI bump up actions including apptainer 1.4.4 -> 1.5.2 update msvc-wine
July 2, 2026
VStyle Curate
Version updated for https://github.com/hack-ink/vibe-style to version v0.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Sync language check structure by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/35 Roll dependencies by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/81 Speed up vstyle tune telemetry by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/82 Full Changelog: https://github.com/hack-ink/vibe-style/compare/v0.2.1...v0.2.2
July 2, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.368.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/6a3f3b3419536de769697931aecf26e2e0d10df8 with plugin-scanner 2.0.968.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.367...v1.2.368
July 2, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.368.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.368
July 2, 2026
Supply Chain Guard
Version updated for https://github.com/homeofe/supply-chain-guard to version v5.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.5.0 (2026-07-02) Community batch: all 8 seeded issues shipped, hardened by an adversarial release gate
Implements every open issue (#40-#47) in one release. Before tagging, a 4-lens adversarial verification gate reviewed the full diff and BLOCKED the first candidate with 6 confirmed findings - all fixed here (details below). 35 new tests (1057 total).
July 2, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(shell): resolve agent-guard without a PATH install for the bang guard by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/94 release: v1.7.0 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/95 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.6.0...v1.7.0
July 2, 2026
Official Junie GitHub Action
Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Junie]: Update Junie CLI Version to 2144.7 in Files by @mashan555 in https://github.com/JetBrains/junie-github-action/pull/172 Full Changelog: https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.6
July 2, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.80.4.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.80.4 (2026-07-02) Bug Fixes (core): vertex schema fallback, mcp log dedup, safe serialization, timeout handling (2889ed2)
July 2, 2026
BPFCompat eBPF Compatibility Gate
Version updated for https://github.com/Kernel-Guard/bpfcompat to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix(ci): prefetch quirk-library images before validation in the publish lane (#76) (c7ef4fb) chore(release): prepare v0.3.0 — changelog + version refs (#75) (b2ef03e) docs: consolidate experimental tracks into docs/experimental.md (#73) (8a910a5) feat(examples): ebpf-go validation recipe — loader example + cookbook (#72) (7eed351) feat(ci): publish the quirk-library matrix to GitHub Pages weekly (#71) (1d75677) feat(action): command-mode inputs + built-in matrix names for the GitHub Action (#70) (00e2017) docs: drop internal “Repository Hygiene” section from README (#69) (b127315) fix(docs): readable contrast in test-command screenshot (#68) (2491a69) feat(cli): add test-command verb + README screenshot of a real run (#67) (88971fe) docs: surface command mode as a core feature + soften Falco loader claim (#66) (c790219)
July 2, 2026
L10n.dev AI Localization Automation
Version updated for https://github.com/l10n-dev/ai-l10n to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: implement safety improvements by removing apiKey field and refactoring key management by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/47 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.7.1...v1.8.0
July 2, 2026
crabd
Version updated for https://github.com/louisescher/crabd to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: review verdict labels, comment-only reviews, web search by @louisescher in https://github.com/louisescher/crabd/pull/4 feat: Delete crabd.yml, prepare for public release by @louisescher in https://github.com/louisescher/crabd/pull/6 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/5 New Contributors @louisescher made their first contribution in https://github.com/louisescher/crabd/pull/4 Full Changelog: https://github.com/louisescher/crabd/compare/v0.1.0...v0.1.1
July 2, 2026
moult-action
Version updated for https://github.com/moult-rb/moult-rb to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First gem release since 0.1.0 (v0.2.0 was tagged but its publish failed; its changes are included here). Published to RubyGems as moult.
moult-action The bare uses: moult-rb/moult-rb@v1 workflow now works out of the box: the action installs moult from its own checkout (no Gemfile needed in your repo) and moult-cloud-url defaults to https://moultrb.com. Actionable first-run errors: a missing permissions: id-token: write now says exactly that instead of a Ruby backtrace; non-2xx responses from GitHub’s token endpoint are reported with status and body. Pull requests from forks are gated in CI but skip the upload with a notice — GitHub issues no OIDC identity to fork PRs. base-sha defaults to the PR base branch (or the merge queue’s base SHA), falling back to the repository default branch — repos whose base branch isn’t main no longer fail their first PR scan. merge_group events are supported as pr scans; pull_request_target is rejected in auto mode (it checks out the base branch, which would silently gate an empty diff as a pass). Gem Moult::CloudUpload.projection — the sanitised upload payload builder (allow-listed keys, absolute paths stripped). License changed from MIT to Apache-2.0. Full details in CHANGELOG.md.
July 2, 2026
DeepRabbit Code Review
Version updated for https://github.com/n0namedeveloper/DeepRabbit to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Github Marketplace release.
Full Changelog: https://github.com/n0namedeveloper/DeepRabbit/compare/v1.1.0...v1.1.1
July 2, 2026
Parkstatic Build and Deploy
Version updated for https://github.com/ParkStatic/action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bump pnpm/action-setup from v4 to v6 (0b8282d) CI: add Astro, SvelteKit, Remix, and Nuxt fixtures to the test matrix (377d196) Support Astro, SvelteKit, Remix, and Nuxt static builds (2bb9389) Add framework-compatibility test suite and offline build inputs (b31ebe4) Initial release (6857aff)
July 2, 2026
Blog to Newsletter
Version updated for https://github.com/peterpeterparker/blog-to-newsletter-action to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: deny closing footer with name and website by @peterpeterparker in https://github.com/peterpeterparker/blog-to-newsletter-action/pull/5 Full Changelog: https://github.com/peterpeterparker/blog-to-newsletter-action/compare/v0.0.3...v0.0.4
July 2, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed litmus-v11 — C-02 gains expected-upstream inference, fixing a first-party-egress false positive.
An honest API-wrapper server — a tool that transparently calls the API it advertises (openai_chat → api.openai.com) — made an undeclared egress attempt and was capped at D, even though the upstream is the very API its own surface names. Before an undeclared host is now counted as overreach, the harness infers whether it is a plausible upstream for the server’s own tool surface: a host named verbatim in the tool text (strong), or an egress host whose registrable label matches a non-generic brand token drawn from the surface and the package owner/name (medium, plain-TLD hosts only). A match reclassifies the attempt from overreach into an informational egress-inferred finding — disclosure, not exoneration.
July 2, 2026
Prowler Security Scan
Version updated for https://github.com/prowler-cloud/prowler to version 5.32.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New features to highlight in this version Enjoy them all now for free at https://cloud.prowler.com
🔎 Findings Triage [!NOTE] This feature is available exclusively in Prowler Cloud and Prowler Enterprise with a subscription.
Triage findings straight from the Findings view. Each finding gets a triage status you can move through its lifecycle:
July 2, 2026
Assay - AI Agent Security
Version updated for https://github.com/Rul1an/assay-action to version v3.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3 is the current major: verify, lint, and diff evidence bundles from AI agent runs in CI, with coding-agent sandbox governance and in-toto/DSSE bundle attestation.
What v3 carries
sandbox-command: run a coding agent under assay sandbox and verify the resulting evidence bundle in the same job. attest-key: in-toto/DSSE attestation over the bundle (assay evidence attest). The v2.1 AI Agent Security feature set: compliance packs, BYOS push, artifact attestation, coverage badges, PR summaries, SARIF for code scanning. v3.0.1 fixes
July 2, 2026
CDK Lambda Size Gate
Version updated for https://github.com/schuettc/cdk-lambda-size-gate to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 16da0508205b06be18de0adb4a721ba5fc07182a: ci: e2e verification of the published action (v1.0.0 + v1, linux + windows) (@schuettc) 1d399dc296ec3f1977e607a204deb0fc133a8109: fix(action): shorten description under Marketplace 125-char limit (@schuettc)
July 2, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.13.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.13.0 Released 2026-07-02.
Run-safety guardrails and per-role endpoint configuration.
Fixes (run safety) GitHub backlog auto-sync is now opt-in and off by default. Previously a run in a repository with open GitHub issues would pull every open issue into the backlog before task scoping, which could silently discard a seeded goal and spawn work against the entire issue list. Enable it explicitly with the github.sync_backlog seed config key (or the BERNSTEIN_SYNC_GITHUB_BACKLOG env override). (#2178) A seeded goal is no longer silently dropped when the backlog is non-empty: the run now prints a loud warning naming the precedence and how to force the goal, instead of quietly planning from the backlog. (#2178) Agent worktree merges refuse to land on the repository default branch. The merge and push path resolves the protected default (origin/HEAD, then init.defaultBranch, then the conventional names, treating both main and master as protected when the remote head is ambiguous) and refuses to merge or push agent work onto it, recording the refusal, so a run started from a default-branch checkout can no longer push unreviewed commits straight to the trunk. (#2178) Features (per-role model configuration) role_model_policy entries gain optional base_url and api_key_env next to model/provider, so different roles can target different OpenAI-compatible endpoints in one workflow (for example a fast manager endpoint and cheaper worker endpoints). api_key_env names an environment variable and is validated against the same fail-closed provider allowlist as the runner. YAML anchors give reuse across roles with no new file format. Absent fields keep today’s behavior. (#2159) ModeProfile gains top_p, top_k, and max_tokens beside its existing temperature, and the previously-deferred apply_mode_to_spawn wiring is completed so a mode profile’s sampling parameters actually reach the spawn and the runner manifest. (#2159) Opt-in builtin tools for the openai_agents runner, for runs without an MCP gateway, selected by tool_source: builtin (the gateway remains the default). read_file, write_file, and list_dir are workdir-confined (absolute and parent-escape paths are rejected). run_command is a restricted process-exec primitive: bare-name commands only, shell interpreters blocked, resolved against PATH, available only under a configured OS sandbox provider or an explicit opt-in; its filesystem confinement is the OS sandbox, not the builtin. Every builtin call is recorded to the run event log so a gateway-free run stays auditable. (#2159) Quality Resolved refurb FURB123 findings in the OWASP control-map builders.
July 2, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.0 (2026-07-02) ⚠ BREAKING CHANGES pipr init –types-only and –no-types are removed and generated .pipr/types/pipr-sdk.d.ts is no longer written; types come from the installed @usepipr/sdk package. structure runtime action logging (#10) consolidate public API contracts (#9) Features consolidate public API contracts (#9) (01db150) support installable npm dependencies in .pipr config (#14) (97794bc) Code Refactoring structure runtime action logging (#10) (64addf1)
July 2, 2026
Repository Create
Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.74.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.74.0
1.74.0 (2026-07-02) ✨ Features updates (328fff6)
July 2, 2026
Frisk — AI supply-chain scan
Version updated for https://github.com/Thandv/frisk to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release. Static, zero-execution scanner for AI-agent content (MCP servers, skills, plugins): RCE, secret exfiltration, destructive ops, prompt-injection, tool-poisoning, hidden-unicode. Rug-pull detection (lock/verify), OWASP LLM Top 10 mapping, SARIF, GitHub Action, and an MCP server to vet-before-install. Install: pip install frisk-scan
July 2, 2026
UnityInFlow Spec Compliance
Version updated for https://github.com/UnityInFlow/spec-ci-plugin to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First stable Marketplace release of the UnityInFlow Spec Compliance action.
What’s included Typed status and report action outputs (matching the runtime core.setOutput calls) injection-scanner-version default bumped to v0.0.2 — the tag carrying the Linux musl binaries the action downloads at runtime Deterministic committed dist/ (no sourcemaps) guarded by a git diff --exit-code dist/ staleness gate in CI Public/fork CI runs secretless on GitHub-hosted runners; release automation stays on org self-hosted runners Moving v1 tag maintained automatically on release publish Usage - uses: UnityInFlow/spec-ci-plugin@v1
July 2, 2026
Polder Drift — Design System Drift Alerts
Version updated for https://github.com/usepolder/drift to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Polder Drift now works with any design system — including your in-house one. Point library_paths at a checkout of your DS repo (source-only monorepo workspaces work too), and generate the look-alike detection data straight from your DS’s own source:
July 2, 2026
configure-huawei-cloud-credentials
Version updated for https://github.com/vbem/configure-huawei-cloud-credentials to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/configure-huawei-cloud-credentials/compare/v0.0.2...v1.0.0
July 2, 2026
Install The Hive Skill
Version updated for https://github.com/yuzuruu29/the-hive-skill to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Hive Skill v0.1.0 Initial public release of The Hive Skill, an open-source autonomous multi-agent orchestration skill for agentic coders.
The Hive Skill turns one AI coding agent into a structured six-role council:
Role Table Role Responsibility Queen Coordinates the council, makes final decisions, and ensures the goal is met. Scout Explores the codebase and gathers necessary context. Architect Designs the solution and plans the changes. Forger Writes the code and implements the Architect’s plan. Sentinel Validates the changes, runs tests, and ensures quality. Scribe Documents the process and writes the final report. What is included SKILL.md core skill definition Six council role files Autonomous execution loop Token efficiency mode Compressed role output mode Default invocation behavior Anti-slop rules Validation rules Final and blocked report formats OpenCode / OpenCode Go adapter Claude Code adapter Codex adapter Generic .agents adapter Install scripts for Bash and PowerShell GitHub Action wrapper Security policy Apache-2.0 license Supported agentic coding workflows The Hive Skill is designed for:
July 2, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.367.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.367
July 2, 2026
Skill Probe - AI Agent Skill Auditor
Version updated for https://github.com/HystonKayange/skill-probe to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed skill-probe in your pipeline, gating on statistics instead of vibes The CI question isn’t “are my skills perfect?” — it’s “did this PR make any skill worse?” Activation is stochastic, so raw-rate comparisons make CI flaky. v0.9.0 makes the gate honest.
July 2, 2026
MLX Model Doctor
Version updated for https://github.com/IonDen/mlx-model-doctor to version v0.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v0.6.2: memory pass/fail semantics and hardening fixes by @IonDen in https://github.com/IonDen/mlx-model-doctor/pull/22 Full Changelog: https://github.com/IonDen/mlx-model-doctor/compare/v0.6.1...v0.6.2
July 2, 2026
zizmor - static analysis tool for Actions workflows
Version updated for https://github.com/its-me/action.zizmor to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of the action.
July 2, 2026
NeuroLink AI
Version updated for https://github.com/juspay/neurolink to version v9.80.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.80.3 (2026-07-02) Bug Fixes (vertex): reserve final_result step + graceful cap recovery in native Anthropic loop (ee44e60), closes #1123
July 2, 2026
OLIVE Action
Version updated for https://github.com/kakao/olive-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 OLIVE Action v1 - 첫 번째 릴리즈 📋 릴리즈 개요 OLIVE Action의 첫 번째 공식 릴리즈입니다. 이 Action은 GitHub Actions에서 OLIVE CLI를 사용하여 오픈소스 라이선스 의무사항 준수를 자동화하는 도구입니다.
✨ 주요 기능 🔍 자동 의존성 분석 Pull Request 생성 시 소스코드 의존성을 자동으로 분석 다양한 프로그래밍 언어 지원 (Python, Node.js, Java, Rust, Ruby, Dart, Flutter 등) ORT (OSS Review Toolkit) 기반의 정확한 의존성 추출 💬 PR 코멘트 자동 작성 분석 결과를 Pull Request에 자동으로 코멘트 작성 라이선스 정보, 매핑된 컴포넌트, 매핑되지 않은 의존성 목록 제공 실패 시에도 적절한 에러 메시지 자동 작성 🔗 OLIVE Platform 연동 분석 결과를 OLIVE Platform으로 자동 전송 오픈소스 라이선스 및 취약점 관리 지원 프로젝트별 라이선스 의무사항 추적 📦 분석 결과 저장 GitHub Artifacts를 통한 상세 분석 결과 저장 dependency.csv, dependency.json, mapping.csv, mapping.json, unmapping.csv 파일 제공 설정 파일 (local-config.yaml) 보관 🛠️ 기술적 특징 컨테이너 기반 실행 Docker 컨테이너 환경에서 격리된 실행 다양한 개발 도구가 사전 설치된 통합 환경 안정적이고 재현 가능한 실행 환경 다중 언어 지원 Python: 3.11.10, pip, pipenv, poetry, conan Node.js: 20.14.0, npm, yarn, pnpm, bower Java: Gradle 8.13, OpenJDK 11 Rust: 1.72.0 Ruby: 3.3.5, bundler, cocoapods Dart/Flutter: 2.18.4/3.24.4 PHP: 8.3, composer Android: Android SDK, command-line tools 모듈화된 구조 6단계 실행 프로세스로 명확한 워크플로우 각 기능별 분리된 스크립트로 유지보수성 향상 사용자 정의 설정 파일 지원 🚀 사용법 기본 사용법 name: OLIVE Action on: pull_request: types: [opened, synchronize, reopened] branches: [main, develop] permissions: contents: read issues: write pull-requests: write jobs: olive-scan: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Run OLIVE Action uses: kakao/olive-action@v1 with: olive-token: ${{ secrets.OLIVE_TOKEN }} github-token: ${{ secrets.GITHUB_TOKEN }} 고급 설정 - name: Run OLIVE Action with custom settings uses: kakao/olive-action@v1 with: olive-project-name: "my-custom-project" olive-token: ${{ secrets.OLIVE_TOKEN }} github-token: ${{ secrets.GITHUB_TOKEN }} source-path: "./src" user-config-path: "./user-config.yml" artifact-retention-days: "7" comment-on-pr: "true" analyze-only: "false" debug: "false" 🔧 입력 파라미터 파라미터 설명 필수 기본값 olive-token OLIVE Platform API 토큰 ✅ - github-token PR 코멘트 작성용 GitHub 토큰 ✅ - olive-project-name OLIVE Platform 프로젝트 이름 ❌ 저장소 이름 source-path 분석할 소스코드 경로 ❌ ./ user-config-path 사용자 정의 config 파일 경로 ❌ "" artifact-retention-days 아티팩트 보관 기간 (일) ❌ 30 comment-on-pr PR에 코멘트 작성 여부 ❌ true analyze-only 분석만 수행하고 Platform 연동 생략 ❌ false debug 디버그 모드 활성화 ❌ false 📊 출력 결과 GitHub Artifacts dependency.csv, dependency.json: 의존성 분석 결과 mapping.csv, mapping.json: 컴포넌트 매핑 결과 unmapping.csv: 매핑되지 않은 의존성 목록 local-config.yaml: OLIVE CLI 설정 파일 PR 코멘트 OLIVE CLI 버전 및 프로젝트 정보 라이선스 분석 결과 요약 매핑된 컴포넌트 및 매핑되지 않은 의존성 목록 아티팩트 다운로드 링크 🚨 사전 준비사항 1. OLIVE Platform 토큰 발급 OLIVE Platform에서 API 토큰 발급 토큰 발급 가이드 참고 2. GitHub Secrets 설정 OLIVE_TOKEN: OLIVE Platform API 토큰 GITHUB_TOKEN: GitHub Actions 기본 토큰 (자동 제공) 🔍 실행 단계 소스 위치 검증 - 분석할 소스코드 경로 확인 OLIVE CLI 초기화 - 프로젝트 설정 및 토큰 검증 의존성 분석 - 소스코드 의존성 추출 및 분석 컴포넌트 분석 - 의존성을 OLIVE 컴포넌트에 매핑 라이선스 분석 - 라이선스 정보 추출 및 분석 OLIVE Platform 연동 - 분석 결과를 Platform으로 전송 🛡️ 보안 및 안정성 격리된 실행 환경: Docker 컨테이너를 통한 안전한 실행 토큰 검증: 실행 전 필수 토큰들의 유효성 검증 에러 처리: 실패 시 자동 정리 및 에러 리포팅 리소스 관리: 컨테이너 자동 정리로 메모리 누수 방지 📚 문서 및 지원 사용 가이드: README.md OLIVE Platform: https://olive.kakao.com/ OLIVE CLI: https://github.com/kakao/olive-cli 📄 라이선스 이 프로젝트는 Apache License 2.0 하에 배포됩니다.
July 2, 2026
Night Sky Contrib
Version updated for https://github.com/maxmode-now/night-sky-contrib to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release.
night / dawn / city themes real moon phase, longest streak constellation, language mountains or skyline zero dependencies, works with the default GITHUB_TOKEN
July 2, 2026
Pollinations PR Reviewer
Version updated for https://github.com/mikl-shortcuts/Pollinations-PR-Reviewer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Small Update: Integrate minimatch Improve comment parsing Add PR descriptions passing Add reasoning-effort and timeout parameters Improve logging Bug fixes
July 2, 2026
Synaptic PR Review
Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New Features Repository Memory Rules — teach the bot your team’s coding conventions Comment @synaptic-ai remember: <rule> on any PR to add a rule Rules stored in .synaptic/rules.json and enforced during every review Collaborator verification before adding rules Dedicated extraction prompt for faster processing 🐛 Bug Fixes Fix pr_number used before defined in main_remember() Fix direct engine not outputting REMEMBER_RULE_JSON Move collaborator check before LLM extraction to avoid wasted API calls Add collaborator check to process_remember_from_comment() Filter find_latest_comment_with_remember() by bot author + review signature 📝 Documentation Add preview screenshots (PR Overview, Issue Summary, Inline Comments) to README Full Changelog: https://github.com/minhphu102003/ai-pr-review-action/compare/v0.1.3...v0.2.0
July 2, 2026
moult-action
Version updated for https://github.com/moult-rb/moult-rb to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update README.md by @GoodPie in https://github.com/moult-rb/moult-rb/pull/2 Add GitHub Actions workflow for Moult integration by @GoodPie in https://github.com/moult-rb/moult-rb/pull/3 Support baseline scan uploads in the composite action by @GoodPie in https://github.com/moult-rb/moult-rb/pull/4 New Contributors @GoodPie made their first contribution in https://github.com/moult-rb/moult-rb/pull/2 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.1.0...v0.2.0
July 2, 2026
Go Proxy Cache Updater
Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.11.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.11 (2026-07-02)
July 2, 2026
Open Delivery Spec
Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 👻 Maintenance ci: add scheduled workflow to bump the pinned CLI version by @shenxianpeng in #45 chore: pin default cli-ref to a stable release for reproducibility by @shenxianpeng in #43 Full Changelog: https://github.com/open-delivery-spec/validate-action/compare/v0.2.0...v0.2.1
July 2, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.22.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release shipping the security and correctness fixes from the 2026-07-02 engineering review.
False-pass paths (grading correctness):
A1 — iptables add-op is now atomic (set -e): a partial rule insertion exits non-zero so the caller falls back to --internal instead of running with broken NAT and silently missing IP-literal/DoH egress A2 — readOnlyHint:true can no longer bypass the exercise skip gate: unsafeToExerciseToolNames now checks the broad STATE_CHANGING_VERBS set regardless of the annotation, so a lying swap_*/buy_*/approve_*/mint_* tool is never actively bait-called A3 — content in a JSON-RPC error response is now scanned: callToolArgs carries errorText; probes 1.2, 1.3 run scanInjection on it, probe 3.1 runs internalsLeak A5 — MCP progress forwarding: void sendNotification(…) → .catch(() => {}) so a client disconnect during a run can’t kill the server process Sandbox observability:
July 2, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.6.0
July 2, 2026
Notify QA Wolf on Deploy
Version updated for https://github.com/qawolf/notify-qawolf-on-deploy-action to version v2.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.0.1 Fix the ephemeral-environment input being ignored. Ephemeral deployments are now notified as ephemeral instead of as a regular GitHub deployment, and deployment-url is required when ephemeral-environment is true. v2.0.0 The action now runs on Node 24. v1.2.1 Allow ephemeral-environment as a valid input param v1.2.0 Don’t guess a recent PR number based on SHA for non-PR events v1.1.5 Allow pull-request-number as a valid input param v1.1.4 Fix a problem where the sha passed in via merge_group events was wrong, causing commit checks to never complete v1.1.3 Update README.md to include deployment_type examples v1.1.2 Correct code sample in README where GITHUB_TOKEN is being passed as a secrets instead of an env v1.1.1 Improve logging to facilitate debugging v1.1.0 Expose an eventId on errors Output the environmentId on attemptNotifyDeploy v1.0.4 Extract information from Github Event and send it to attemptNotifyDeploy v1.0.3 Add qawolf-base-url optional input v1.0.2 Fix action name on documentation v1.0.1 Fix build problem and add branding v1.0.0 Initial version
July 2, 2026
Build & Push to Registry
Version updated for https://github.com/relybytes/actions-docker-build-push to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Build & Push to Registry v1.0.0 First stable release of actions-docker-build-push, a GitHub Action for building Docker images and pushing them to container registries with a predictable naming convention.
Main features Build Docker images using Docker Buildx Push images to GitHub Container Registry by default Support any container registry, including Docker Hub, Harbor, OVHcloud Managed Private Registry, and custom registries Default authentication with GitHub actor and GITHUB_TOKEN Automatic image naming based on branch, tag, or pull request Environment suffixes such as prod, dev, staging, rc, hotfix, feat, and pr-{number} Auto-generated version tags using YYYY-MM-DD.shortsha Optional :latest tag on main/master builds Support for additional tags Support for multi-platform builds Support for build arguments Support for multi-stage Dockerfile targets Automatic OCI labels Optional local build validation with push: "false" Output image reference, repository, version, suffix, tags, digest, and build timestamp Default behavior With no registry credentials passed, the action defaults to GitHub Container Registry:
July 2, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.6.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The v1.7.5 cocoindex install step ran ccc --version as a sanity check, but the typer app doesn’t expose a –version flag so it raised a red “No such option ‘–version’” error box in the Actions UI. The || true suppression meant the step still succeeded, but the visible error box was misleading.
July 2, 2026
Gated automerge
Version updated for https://github.com/run-action/automerge to version v1.2.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed docs: simplify description (#4) (46cd9d2) docs: rename action to gated automerge (d80ec1c) docs: add required checks read permissions (240cb58) feat: add option to disable require-checks (2362745) deps: bump nixpkgs in the dependencies group across 1 directory (#2) (77ebbe4) feat: add support for skip-labels (7cd48f4) Auto update internal actions (bb2e6d1) Add release workflow (6fc2ea8) Add linting and dependabot (499faef) Add action.yaml with examples (0f0d6da)
July 2, 2026
runs-on/action
Version updated for https://github.com/runs-on/action to version v2.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/runs-on/action/compare/v2.1.2...v2.2.0
July 2, 2026
Bernstein — Multi-Agent Orchestration
Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.11.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.11.0 Released 2026-07-02.
Features The openai_agents runner accepts optional sampling and endpoint parameters: temperature, top_p, top_k, base_url, and api_key_env on the runner manifest, flowing into the SDK client and model settings. Absent fields keep the previous behavior byte-identical. When base_url is set the runner switches to the chat-completions API and excludes the custom client from tracing, so a third-party key is never sent to the default tracing endpoint. Every effective parameter is logged in the runner start event, so runs stay self-describing. Design validated in daily runs by @shanemmattner (#2159). (#2173) api_key_env is fail-closed: it must name a known LLM provider key from the built-in allowlist; anything else requires the operator to allow it via BERNSTEIN_ALLOWED_API_KEY_ENVS on the host, which a repository cannot set. Requesting sampling parameters on an adapter without the new SUPPORTS_SAMPLING_PARAMS capability fails loudly instead of silently dropping them. (#2173) SDK runners now write heartbeats, so they are visible to the stall watchdog between spawn and exit. (#2173) Fixes The Docker sandbox path from v2.10.0 is hardened: each spawned agent gets its own sandbox session (one exec timeout no longer tears down every agent’s container), committed work is bundled out of the container and fetched into the host repo under sandbox/<session_id> refs, sandbox lifecycle events land in the HMAC-chained audit log with emissions serialized so concurrent lifecycles cannot fork the chain, and provisioning probes task-server reachability and warns on daemons without host networking. (#2162, #2172) The bernstein worker loop can spawn agents again: it constructed the spawner with arguments that never existed and raised TypeError on the first claimed task. The server URL now also reaches spawned agents through the environment allowlist. (#2163, #2171) Dependencies Routine CI action digest updates (github/codeql-action, docker/setup-buildx-action).
July 2, 2026
Skyhook Docker Multi-Registry Build Push
Version updated for https://github.com/skyhook-io/docker-build-push-action to version v1.5.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.5.3 (2026-07-02) Bug Fixes run bundled Docker actions on the Node 24 runtime (#8) (526d49e)
July 2, 2026
Pipr Review
Version updated for https://github.com/somus/pipr to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.3 (2026-07-02) Bug Fixes gate releases on main ci (#7) (eb479e0)
July 2, 2026
DProvenanceKit regression gate
Version updated for https://github.com/Therealdk8890/dprovenancekit-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch over v1.1.0: the golden-context / candidate-context inputs now resolve through the runs subcommand (available in every 0.3.x SDK) instead of requiring gate CLI flags newer than the PyPI release. Caught by this repo’s smoke test before any user hit it. The v1 tag points here.
July 2, 2026
Agents Shipgate
Version updated for https://github.com/ThreeMoonsLab/agents-shipgate to version v0.14.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agents Shipgate v0.14.0
July 2, 2026
Podcast Creator
Version updated for https://github.com/xDevMe/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/xDevMe/podcast-generator/commits/v1.0
July 2, 2026
AI-Driven ADR Enforcer
Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.3...v1.1.5
July 2, 2026
Setup Prolog
Version updated for https://github.com/fabasoad/setup-prolog-action to version v1.1.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in https://github.com/fabasoad/setup-prolog-action/pull/9 Full Changelog: https://github.com/fabasoad/setup-prolog-action/compare/v1.1.1...v1.1.2
July 2, 2026
Setup Uiua
Version updated for https://github.com/fabasoad/setup-uiua-action to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in https://github.com/fabasoad/setup-uiua-action/pull/7 Full Changelog: https://github.com/fabasoad/setup-uiua-action/compare/v0.1.2...v0.1.3
July 2, 2026
Fallow - Codebase Intelligence
Version updated for https://github.com/fallow-rs/fallow to version v2.104.0.
This action is used across all versions by 235 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights This release is heavy on CSS intelligence. fallow health --css now understands CSS-in-JS (styled-components, emotion, linaria, vanilla-extract, StyleX, Panda) as first-class, ships a second styling-health quality axis, and adds a design-token blast-radius index. Plus a staged human review walkthrough, an opt-in unused-prop exemption, and a batch of framework false-positive fixes.
July 2, 2026
accessibility-scanner
Version updated for https://github.com/github/accessibility-scanner to version v3.3.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 43 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed New Features Add group_by option to the accessibility scanner by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/239 Add dry_run option to the accessibility scanner by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/232 Distinguish wcag vs best practice by @kzhou314 in https://github.com/github/accessibility-scanner/pull/233 Match axe findings by rule and report all failing elements by @kzhou314 in https://github.com/github/accessibility-scanner/pull/240 Disable reopen wontfix by @kzhou314 in https://github.com/github/accessibility-scanner/pull/234 Update reflow-scan text to improve clarity and reference WCAG 2.2 by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/231 Dependency/documentation updates chore(deps): Bump ruby/setup-ruby from 1.307.0 to 1.308.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/218 chore(deps-dev): Bump the npm-minor-and-patch group across 5 directories with 3 updates by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/219 chore(deps): Bump ruby/setup-ruby from 1.308.0 to 1.310.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/220 chore(deps): Bump puma from 8.0.1 to 8.0.2 in /sites/site-with-errors in the bundler-minor-and-patch group by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/221 chore(deps): Bump ruby/setup-ruby from 1.310.0 to 1.311.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/225 chore(deps): Bump ruby/setup-ruby from 1.311.0 to 1.313.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/227 chore(deps-dev): Bump vite from 8.0.12 to 8.0.16 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/228 chore(deps-dev): Bump @types/node from 25.9.0 to 26.0.0 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/236 chore(deps-dev): Bump undici from 6.24.1 to 6.27.0 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/237 chore(deps): Bump the github-actions group across 4 directories with 2 updates by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/235 chore(deps): Bump concurrent-ruby from 1.3.5 to 1.3.7 in /sites/site-with-errors by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/238 New Contributors @taarikashenafi made their first contribution in https://github.com/github/accessibility-scanner/pull/231 @kzhou314 made their first contribution in https://github.com/github/accessibility-scanner/pull/234 Full Changelog: https://github.com/github/accessibility-scanner/compare/v3.2.0...v3.3.0
July 2, 2026
TrustCheck Package Scanner
Version updated for https://github.com/Halfblood-Prince/trustcheck to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published from immutable commit e6660a53c73391a10e8e721e3a245b25e3289b4b. The release workflow publishes PyPI, GitHub Action, Snap Store, and GHCR Docker distributions after shared tag verification, QA, matrix, and coverage builds.
Release artifacts:
dist/* dist/SHA256SUMS.txt dist/*.cdx.json standalone trustcheck-*-windows-x86_64.exe with checksum unsigned trustcheck-*-store.msix for Microsoft Store submission GHCR Docker images for linux/amd64, linux/arm64, and linux/arm/v7 Verify the direct Windows executable before use:
July 2, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.366.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/320919c7979db097e4d0485e97a0a7675bc59620 with plugin-scanner 2.0.966.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.365...v1.2.366
July 2, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.366.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.366
July 2, 2026
Codex Action
Version updated for https://github.com/icoretech/codex-action to version v0.9.16.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.16 (2026-07-02) Bug Fixes deps: update codex-docker image to v0.142.5 (#46) (fc08eb8)
July 2, 2026
cibuild-action
Version updated for https://github.com/invarnhq/cibuild to version v2.2.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.2.8
July 2, 2026
AIGate AI Git Workflow Guard CLI
Version updated for https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli to version v0.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Added aigate start guided setup routes for quickstart, AI setup, pre-push hooks, release readiness, and full project guard setup. Added aigate test for Git readiness plus detected project test command execution. Added aigate aitest for AI remediation prompt generation and optional Codex, Claude, Gemini, or custom agent execution with --apply. Added repository Claude Code instructions through CLAUDE.md and .aigate/integrations/claude.md. Updated multilingual README, usage, operations, roadmap, AI integration, GitHub Action, examples, and generated HTML overview docs. Extended the reusable GitHub Action to support test and safe aitest prompt generation. Validation npm run ci Release workflow dry run Tagged release workflow publish node src/cli.mjs release-check --npm --language ko Package npm: aigate-cli@0.1.5
July 2, 2026
OSS Security Policy as Code
Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v9.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v9.0.3 This release is the v9.0.3 release of the OSS Security Policy as Code Starter Kit (refine this line before publishing).
Highlights No feature-level changes in this release. Improvements retitle SAST-OSV-068 — the kit ingests OSV verdicts, it is not reachability-aware honor SOURCE_DATE_EPOCH for every outcome-affecting clock read; freeze the suite clock formalize SELF_ATTESTED in the published reports/2.0 schema (9.0.3) build Gemara state maps from pairs to clear a Snyk Code false positive Notes release 9.0.3 (#110) ADR-030 amendment re-grounding the v10.0.0 surface; flip ADR-021 to accepted suppress reviewed Snyk Code false positive via .snyk; keep the gate strict make Snyk Code + Snyk Open Source advisory (continue-on-error) License: Apache-2.0.
July 2, 2026
SnarkGirl
Version updated for https://github.com/mattkelly1991/SnarkGirl to version v1.15.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed SnarkGirl v1.15.3 — The Wiki Ledger + a Living Pitch 📖⚽ The World Cup tournament got two big upgrades: it now lives in your repo’s Wiki, and the pitch actually plays.
The tournament moved to the repo Wiki Standings + match reports are now human-readable, browsable wiki pages organized as World Cup → Season → Match: a Home index of seasons, a Season-{slug} standings page each, and one Season-{slug}-Match-{N} report per PR. No more base64 tokens to shuttle around. Every page carries a keyed HMAC signature footer — change a win from 3 to 4 in the wiki editor and wiki.py verify flags it INVALID. Export a private SGWC_SECRET for a real barrier. Resuming a season is just “clone the wiki.” The user names the season (and its duration) at kickoff. New helper wiki.py (render/verify/verify-all/load-season). Retired the old token.py. The live pitch is alive Players roam their formation and pass the ball, holding shape at each kickoff until someone takes it. A goal is scripted end-to-end: the ball is worked to the scorer, who drives at the net and buries it. A red card sets up a penalty kick — a code red is converted, an agent red is saved by the keeper. Sent-off players walk to a bench at the edge (home top-left, away top-right). The champion & awards now present on the wiki season page (the live arena ends on the standings). Full changelog: https://github.com/mattkelly1991/SnarkGirl/blob/main/CHANGELOG.md
July 2, 2026
Claude Ralph Loop
Version updated for https://github.com/mdelapenya/claude-ralph-github-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes docs: link sbx sandbox docs and document sandbox inputs @mdelapenya (#97) Contributors @mdelapenya
July 2, 2026
Synaptic PR Review
Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.1 Strip model preamble: remove leading text before ## PR Review heading in both OpenCode and direct engine paths OpenCode engine: post_inline.py now always updates summary comment when body changes (preamble or Key Issues stripped) Direct engine: sanitize_review() strips preamble before posting
July 2, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.88.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 2, 2026
semvertag
Version updated for https://github.com/modern-python/semvertag to version 0.8.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed semvertag 0.8.2 — release pipeline on PyPI Trusted Publishing No library changes. The package is identical to 0.8.1; this release exercises the new publish path end-to-end.
CI Releases now authenticate to PyPI via Trusted Publishing (OIDC) instead of a long-lived PYPI_TOKEN secret. uv publish auto-detects the GitHub Actions id-token; the release job runs under a pypi environment that scopes the trusted publisher (#46). Downstream No action required. Nothing about the installed package changes.
July 2, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.5
Support DataWeave reduce With A Default Accumulator
July 2, 2026
PatchFlow Security Scan
Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PatchFlow CLI v0.1.2 Benchmark Results (v1.0) 18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories 5 historical CVE repos: 100% recall, 387K LOC 10 clean repos: 0.094 HC/KLOC, 720K LOC See Benchmark Report v1.0 for details.
July 2, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.4.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed HF Hub checkpoint preflight for architecture-add Issues (REMYX-178) (8a70186) arxiv HTML retry: title-overlap threshold + project-page one-hop + README verification (c6c021f) README: add lerobot #9 (ECoT reasoning supervision) to Examples (85fa29b) Coding-agent prompt: guidance on auto-format scope (be8720d) README: drop the “Recommended” ENVIRONMENTS.md section (82b9549) Recommend ENVIRONMENTS.md + cocoindex as the default setup (9ca24e1) License detection: retry via arxiv HTML on unfavorable buckets (615af84) README: restore smellslikeml/peft #5 as the primary Outrider artifact (e8fb3a0) README: swap smellslikeml/peft #5 for the upstream draft huggingface/peft #3382 (28cfc14) README: add huggingface/peft #3382 (upstream draft) to Examples (bc70d94)
July 2, 2026
nix init
Version updated for https://github.com/spotdemo4/nix-init to version v1.55.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update spotdemo4/better-checkout action to v0.13.0 (#154) (3fc7f0af893590575d0d65b8a2e3fbbdff95fdec) bump: v1.54.1 -> v1.55.0 (d2afabdda2558d6cf558962bbc7dce09ff5e9950) chore(deps): update github actions to v1.54.1 (#153) (4e0f684fbdfd7f3a0f78fe5cfe6702ef984c3370)
July 2, 2026
Repository Create
Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.72.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.72.0
1.72.0 (2026-07-02) ✨ Features updates (da42214) 📚 Documentation update .github/index.md (b643fff)
July 2, 2026
Update Uclusion
Version updated for https://github.com/Uclusion/update-job to version v1.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed J-all-329 Only mark job complete when it has no open tasks (bd99322) T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19) T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb) fix: Only extract job ids. (340d9bb) fix: move to node 24.x (a19c034) fix: move to node 24.x (ab6d493) fix: link doc (c83286a) fix: space in view name (ff4ac90) fix: space in view name (d0c570f) fix: urlencode (f66608d)
July 2, 2026
Velda Run job
Version updated for https://github.com/velda-io/action to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release
July 2, 2026
install spaces
Version updated for https://github.com/work-spaces/install-spaces to version v0.17.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.1 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/32 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.16.0...v0.17.1
July 2, 2026
Run PHP Scoper
Version updated for https://github.com/WPTechnix/run-php-scoper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 Initial release of the PHP-Scoper Action, a composite GitHub Action for scoping PHP project dependencies using humbug/php-scoper.
What’s Included PHP version selection: Choose any PHP version using php-version (default: 8.2).
Flexible PHP-Scoper versions: Use a specific release tag, version constraint, or branch with scoper-version.
July 1, 2026
ansede-static
Version updated for https://github.com/mattybellx/Ansede to version v5.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [5.0.0] — 2026-06-27 Added Rust Pattern Engine — Native regex matching via PyO3 (ansede_rust_core), 3.6x faster on large files with graceful Python fallback Java Tree-Sitter AST Analyzer (java_ast_analyzer.py) — Replaces regex heuristics with accurate AST parsing. 9 checkers: CWE-89, CWE-78, CWE-328, CWE-918, CWE-601, CWE-79, CWE-798, CWE-22, CWE-862 4 New Detectors: CWE-942 (CORS wildcard), CWE-94 (Jinja2 SSTI), CWE-362 (TOCTOU), CWE-862 (Spring Actuator) Precision Benchmark Harness (benchmarks/precision_benchmark.py) — Multi-language, multi-repo precision tracking with per-CWE heatmaps is_framework_internal() context filter — Suppresses findings in framework/library internals (Flask src/, Express lib/) 21-repo scale proof — Validated across 7 languages with 99%+ precision on clean code Changed — Precision (99.4% FP Reduction) Calibration: Removed bare method names (exec, query, execute, raw) from callee sets to prevent Mongoose/ORM false positives Calibration: JS-023 regex anchored with (?<!\.) to prevent Browserify .require() false positives Calibration: Extended ambiguous callee guard to resolve/join for path traversal Calibration: JS-018 __proto__:null now recognized as defensive pattern, not prototype pollution Calibration: Java write() XSS check requires HTTP response receiver, not JSON writer Calibration: 9 CVE benchmark severity thresholds corrected (MEDIUM→MEDIUM, not HIGH) Calibration: CWE-295, CWE-502, CWE-532 added to test-file noise filter Changed — Performance (96% Faster) AST walk cache: Pre-computed per-function node lists shared across all 49 Python rules _rule_24 fix: Module-level AST walk moved outside per-function loop (20x → 1x) Lazy symbolic guards: Skip when no findings or conditionals present Lazy datascience rules: Skip for files without DS imports Java regex→AST: Always uses tree-sitter when available, eliminating regex overhead Fixed Windows path handling: \tests\, \examples\, \docs\ backslash patterns in triage filters Empty CWE display: PY-003 assigned CWE-252, PY-044 assigned CWE-1120 Test-file CWE-98 suppression: Dynamic require in test files correctly filtered CVE Recall: 92.7%→100% (164/164 across 5 languages) What’s New Since v4.1.0 100% CVE recall (164/164) — every known vulnerability detected 99.4% FP reduction on 5 clean repos (535→3 findings) 86% FP reduction on 21 repos across 7 languages 96% faster Python scanning (2,600→5,100 LOC/s) 3.6x faster JavaScript pattern matching via Rust engine Java AST analyzer replaces regex, PetClinic: 38→0 findings
July 1, 2026
Claude Ralph Loop
Version updated for https://github.com/mdelapenya/claude-ralph-github-action to version v0.8.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes feat: wrap claude execution in Docker sbx sandbox @mdelapenya (#95) Contributors @mdelapenya
July 1, 2026
FHIR Validator
Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed npm tarball release for @records-fhir/validator@0.4.1. Synced from medvertical/records monorepo.
Install npm install @records-fhir/validator@0.4.1 What’s new in 0.4.1 Patch release for the standalone validator evidence lanes and MII reference workflow. Released with @records-fhir/validation-types 0.1.5.
Added Added validator claim summary generation for publishing the current HL7, MII reference, and FHIR Schema dual-path evidence in one machine-readable artifact. Added FHIR Schema dual-path action reporting so unconfirmed graph/reference buckets remain explicit follow-up work instead of hidden parity debt. Added package-backed terminology diagnostics and local terminology server helpers for deterministic MII/FHIR Schema quality lanes. Changed Hardened the MII reference triangulation workflow with reference-health probes, policy-rule extraction, skip taxonomy, and failed-profile prewarm details. Refreshed the public validator documentation around the 2026-07-01 evidence: 496/496 HL7 executable JSON comparisons, 231/231 measured MII reference parity, and 555-fixture FHIR Schema dual-path coverage. Tightened FHIR Schema graph slicing, reference-target extraction, and pattern diagnostics while keeping the graph path in parallel evidence mode. Fixed Fixed MII package relevance detection so package names containing substrings such as isik are not misclassified as Gematik ISiK packages. Fixed nested profile slice scoping and choice/FHIRPath edge cases uncovered by the MII and FHIR Schema dual-path lanes. Verification Verified with repository lint, stable tests, targeted validator Vitest suites, full affected conformance, MII reference gate, HL7 parity gate, and FHIR Schema dual-path report generation. Matched npm tarballs @records-fhir/validator@0.4.1 — also tagged validator-v0.4.1 @records-fhir/validation-types@0.1.5 The matching GitHub Action release (if any) is published separately under tag v0.4.1 and is not auto-synced; this release covers the npm package only.
July 1, 2026
Agent Security Harness
Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The harness now tests all four layers of the agentic-payments stack. Since the last PyPI release (v4.5.0), two conformance layers landed — this release ships both.
Highlights (v4.5.0 → v4.7.0: 474 → 520 tests, 33 → 36 modules) Merchant-journey layer — NEW (UCP/ACP), #228 ucp_acp_harness.py — 12 tests, stdlib-only, fail-closed reference verifier.
July 1, 2026
PatchFlow Security Scan
Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
July 1, 2026
Create and Configure Repository
Version updated for https://github.com/pdrodavi-group/create-configured-repo to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/pdrodavi-group/create-configured-repo/commits/v1.0.0
July 1, 2026
SkillTotal AI Component Security Scan
Version updated for https://github.com/pezhik/skilltotal to version v0.24.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection/secret precision (ruleset 25): two more FPs on defensive/security content closed, recall-preserving. (1) A -----BEGIN PRIVATE KEY----- format marker held as a string constant (auth code building a PEM, e.g. @ai-sdk/google-vertex) no longer flags ST-SECRET-EMBEDDED — the pattern now requires actual base64 key material after the marker; a real multi-line key still fires. (2) A credential path cited inside a markdown inline-code span in a security guide (`write to ~/.ssh`, e.g. claude-blog) is routed to needs_review instead of ST-SENS-PATH — scoped to markdown, so a JS template literal in code and a bare path in prose still fire. Both removed spurious ST-COMBO-EXFIL escalations. New unit tests + negative corpus samples; FP floor and benign corpus stay at zero.
July 1, 2026
Sensez - Code Quality Feedback
Version updated for https://github.com/popov95s/sensez to version 0.1.6-alpha.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of the Sensez GitHub Action for pull request analysis.
What It Does Posts annotations and optional review comments on duplicated code blocks found in PR diffs. Fail-on-new thresholds let you gate merges on detected duplication. Language Support Python only in this initial release. JavaScript, TypeScript, and Rust support exist in the full CLI but are not yet shipped in the PyPI build used by the action. What Is Sensez? A structural maintainability tool that complements linters and type-checkers. It builds a graph representation of your code to detect structural duplication, dead code and code smell.
July 1, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2.1.1...v2.1.2
July 1, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-repo-sync-action/compare/v2.0.0...v2.0.1
July 1, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.0.0...v2.0.1
July 1, 2026
Rearm Build And Submit Release metadata action
Version updated for https://github.com/relizaio/rearm-docker-action to version 1.13.4.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Address zizmor findings Bump rearm-actions to v1.7.0
July 1, 2026
ReARM Version and Publish Helm Chart Action
Version updated for https://github.com/relizaio/rearm-helm-action to version 1.10.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Address zizmor findings Bump rearm-actions to v1.7.0
July 1, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Behavior changes that replace categorical shape-label guards with measurement-based decisions, and give the selection stage access to workflow-attached tooling (ENVIRONMENTS.md).
Behavior changes Substitution guard removed. shape in ("replacement", "simplification") → auto-Issue short-circuit no longer fires before implementation. Replacement/simplification runs proceed; the path allowlist + check_integration() catch broken diffs on measured evidence. ENVIRONMENTS.md at selection. Loader runs early and threads the body into select_recommendation’s prompt, so the selection agent has workflow-attached tooling (AST-search skills, MCP servers) while verifying candidates. Empty ENVIRONMENTS.md = unchanged behavior. Self-review orphan surfaced, not vetoed. When is_orphan=true, the PR ships with a prominent warning in the body instead of being downgraded to Issue. Upstream measurement-based gates already catch scaffold-shaped diffs. Confabulation check. Extracts path-like tokens from selection_reasoning and verifies each against the workdir. Step-summary shows N of M verified; a 0 of N verified line surfaces confidently-wrong reasoning. Compatibility Backwards-compatible for runs without an ENVIRONMENTS.md file (loader no-ops). No config changes needed.
July 1, 2026
Jira Sprint CalVer
Version updated for https://github.com/RuBAN-GT/jira-sprint-calver-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-01) Bug Fixes Minor update (7402e43)
July 1, 2026
Skyhook Cloud Login
Version updated for https://github.com/skyhook-io/cloud-login to version v1.11.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.11.1 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#2) (d64734d)
July 1, 2026
Skyhook Docker Multi-Registry Build Push
Version updated for https://github.com/skyhook-io/docker-build-push-action to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.0 (2026-07-01) feat!: upgrade Docker actions and drop buildx_install input (#7) (09a68f8) BREAKING CHANGES removed the buildx_install input. docker/setup-buildx-action v4 removed its install input, so the composite no longer exposes buildx_install; the docker build -> docker buildx build alias it enabled is gone. Use the BUILDX_BUILDER env var if that behavior is needed. Claude-Session: https://claude.ai/code/session_011T9ASy4VmRoYrnuTsLd9oU
July 1, 2026
Skyhook GitHub Auth Token
Version updated for https://github.com/skyhook-io/github-auth-token to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.1 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#1) (4d92bbc)
July 1, 2026
Skyhook Login to AWS
Version updated for https://github.com/skyhook-io/login-aws to version v1.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.7.2 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#1) (d7837a6)
July 1, 2026
Skyhook Login to Azure AKS
Version updated for https://github.com/skyhook-io/login-azure-aks to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.1 (2026-07-01) Bug Fixes update author from KoalaOps to Skyhook (92c7dc0) upgrade GitHub Actions dependencies (#1) (65c0a96)
July 1, 2026
Skyhook Login to GCP GKE
Version updated for https://github.com/skyhook-io/login-gcp-gke to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.2.2 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#2) (70f56db)
July 1, 2026
rsync action
Version updated for https://github.com/spotdemo4/rsync-action to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump: v0.0.1 -> v0.0.2 (48fa2b3) ci(release): replace flake-release and npm publish with gh/forgejo cli (f595fd4) chore(deps): update dependency rolldown to ^1.1.4 (#1) (aa20caf) ci(workflows): add rsync tag and release automation (d0abd20) fix(action): parse rsync TLS port with fallback and range checks (e825732) refactor(action): use static rsync releases for tool setup (7739f63) fix(flake): use pkgs.rsync instead of pkgs.pkgsStatic in overlay (9e2dc66) ci: run checks on amd64 and arm64 runner matrix (7eb0273) ci(check): pass rsync auth inputs to workflow step (3398413) build(flake): update inputs and skip rsync itemize test (0ba1338)
July 1, 2026
Setup Tombi
Version updated for https://github.com/tombi-toml/setup-tombi to version v1.1.7.
This action is used across all versions by 130 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This setup-tombi release matches tombi v1.1.7.
Full Changelog: https://github.com/tombi-toml/setup-tombi/compare/v1...v1.1.7
July 1, 2026
Cloudflare Email Sending
Version updated for https://github.com/tourcoder/cloudflare-email-sending to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/tourcoder/cloudflare-email-sending/commits/v1.0.0
July 1, 2026
spaces checkout run
Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.1 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/26 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.16.0...v0.17.1
July 1, 2026
RepoScope Security scanning + AI-code provenance
Version updated for https://github.com/xdun1698/reposcope-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan your codebase for security vulnerabilities and AI-code provenance on every push and pull request — inline PR comments, a build-gating security score, and a shareable HTML report.
New in 1.0.4 Listing name updated to “RepoScope Security scanning + AI-code provenance”. What it does 30 security detectors across 14 languages — secrets, SQL injection, XSS, command injection, TLS misconfigurations, permissive CORS, and weak crypto. AI-code provenance — flags which scanned files are attributed to AI coding tools (Copilot, Cursor, Claude, Codeium, Windsurf, Aider, Devin) in git history, and writes a machine-readable provenance.json record. Local and deterministic — no network, no LLM. Inline PR review comments — one per finding: file, line, severity badge, CWE ID, and a fix hint. GitHub Check run — PASS/FAIL against your score threshold, with annotations. HTML report artifact + build gating (fail-on, threshold) + # reposcope-ignore: suppression. Quickstart - uses: actions/checkout@v4 with: fetch-depth: 0 - uses: xdun1698/reposcope-action@v1 with: token: ${{ secrets.GITHUB_TOKEN }} Source: https://github.com/xdun1698/reposcope-action · Website: https://reposcope.app
July 1, 2026
Setup poly CLI
Version updated for https://github.com/Goldziher/polylint to version v0.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.1.7
July 1, 2026
ReleaseKit – Automated Versioning & Release
Version updated for https://github.com/goosewobbler/releasekit to version v0.38.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed: Fixed independent-group members to be labeled as “bundled” instead of “coupled” in the release summary. (#513, #509) Fixed standing-PR changelog sections to use #### headings instead of bold text, restoring proper spacing within blockquotes. (#511, #508) Fixed bare #N issue references in changelog entry descriptions to be neutralized and deduplicated with appended ref labels. (#510, #507) Full Changelog: https://github.com/goosewobbler/releasekit/compare/0.38.0...0.38.1
July 1, 2026
Vizb Action
Version updated for https://github.com/goptics/vizb to version v0.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(action): preserve scatter settings on merge-deploy by @fahimfaisaal in https://github.com/goptics/vizb/pull/155 feat: add terminal logo banner to install scripts by @fahimfaisaal in https://github.com/goptics/vizb/pull/156 feat: green arrow logs, simplify messages by @fahimfaisaal in https://github.com/goptics/vizb/pull/158 fix(charts): tooltip legend layout and sigma math by @fahimfaisaal in https://github.com/goptics/vizb/pull/159 fix(stats): correct CI formula, zAxis drop, and edge guards by @fahimfaisaal in https://github.com/goptics/vizb/pull/160 docs(readme): add quick example with platform-specific install commands by @fahimfaisaal in https://github.com/goptics/vizb/pull/162 chore(docs): upgrade Astro 6 to Astro 7 with Rust compiler by @fahimfaisaal in https://github.com/goptics/vizb/pull/164 fix(charts): fit y-axis to data range for line and scatter charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/163 fix(charts): size value 3D grid from category counts and cap camera distance by @fahimfaisaal in https://github.com/goptics/vizb/pull/161 chore(ui): upgrade vite 8 and vitest 4 by @fahimfaisaal in https://github.com/goptics/vizb/pull/165 feat(charts): add –symbol and –symbol-size flags for line and scatter by @fahimfaisaal in https://github.com/goptics/vizb/pull/166 feat(scatter): add –visualmap for 2D scatter gradient coloring by @fahimfaisaal in https://github.com/goptics/vizb/pull/169 feat: applicability-rule pipeline + config/ → internal/ move by @fahimfaisaal in https://github.com/goptics/vizb/pull/170 feat(dataset): add –id flag and ?id= URL dataset selection by @fahimfaisaal in https://github.com/goptics/vizb/pull/171 fix(scatter): apply visualMap on large datasets and add house-price example by @fahimfaisaal in https://github.com/goptics/vizb/pull/172 feat(select): solo –select axis mode, multi-stat, and mixed by @fahimfaisaal in https://github.com/goptics/vizb/pull/173 feat(ci): local ACT example, stable id links, and parser fixes by @fahimfaisaal in https://github.com/goptics/vizb/pull/174 fix(sort): apply sort to 1-axis charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/175 docs(charts): add bar and line examples with screenshots by @fahimfaisaal in https://github.com/goptics/vizb/pull/168 Full Changelog: https://github.com/goptics/vizb/compare/v0.13.0...v0.14.0
July 1, 2026
AI Plugin Scanner
Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.357.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/869275bc9c3ab57804fbc0b168b6a98e91c39a3a with plugin-scanner 2.0.957.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.356...v1.2.357
July 1, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.357.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.357
July 1, 2026
PDPL Compliance Scan
Version updated for https://github.com/imohad/pdpl-scanner to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Builds on v1.0.0 with broader detection, fewer false positives, suppression, and a bilingual HTML report. 32 tests; CI green on Python 3.8/3.11/3.12.
New detection PDPL-CB-02 — personal data sent to a foreign third-party processor (analytics, email, CRM, AI, observability, payments: mixpanel, segment, sendgrid, twilio, openai, stripe, datadog, …). Entity-aware severity like CB-01. PDPL-SEC-02 — database/transport TLS disabled (sslmode=disable, ssl_mode="disable", ssl=false). Assisted controls now run in the engine as high-recall LEADs: DSR-02 (soft-delete erasure), SEN-01 (sensitive data without visible encryption), and repo-wide DSR-01 / RET-01 / LB-01. Leads never fail the gate on their own. Accuracy PDPL-SEC-03 placeholder/low-entropy triage: defaults like changeme / your_password downgrade to a medium LEAD; real-format secrets stay critical. Suppression Inline # pdpl-ignore[CONTROL,…], a .pdplignore file (gitignore-style globs), and glob support in --exclude. Reporting & DX Standalone bilingual HTML report (--html); SARIF partialFingerprints for stable code-scanning dedup; --show-pass + passed_controls in JSON. .pre-commit-hooks.yaml, PyPI publish workflow (OIDC), README badges, and community files. Upgrade: uses: imohad/pdpl-scanner@v1 now resolves to v1.1.0.
July 1, 2026
Agent Guard Secret Guardrails
Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(detection): broaden output secret recall (JWT, bearer, more env keys) by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/85 feat(shell): mask ! shell-escape output via agent-guard exec + shell-init by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/86 release: v1.5.0 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/88 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.4.0...v1.5.0
July 1, 2026
datamodel-code-generator
Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.66.2.
This action is used across all versions by 3,234 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update CHANGELOG for 0.66.1 by @dcg-generated-docs[bot] in https://github.com/koxudaxi/datamodel-code-generator/pull/3507 Update release benchmark data by @dcg-generated-docs[bot] in https://github.com/koxudaxi/datamodel-code-generator/pull/3508 Add Modular to Used by list by @koxudaxi in https://github.com/koxudaxi/datamodel-code-generator/pull/3509 Add Pydantic missing sentinel option by @koxudaxi in https://github.com/koxudaxi/datamodel-code-generator/pull/3510 Full Changelog: https://github.com/koxudaxi/datamodel-code-generator/compare/0.66.1...0.66.2
July 1, 2026
AI Commit Review
Version updated for https://github.com/leek/ai-commit-review to version v1.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Allow AI commit review to continue when at least one selected provider produces a valid review. Failed providers are still reported through provider-failures and logged as warnings; the action now fails only when no selected provider completes successfully.
July 1, 2026
Git Velocity Analyser
Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.9.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog
July 1, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.9.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.2 (2026-07-01) Bug Fixes provider: fail fast on expired cloud credentials (#162) (c56fa7d)
July 1, 2026
Synaptic PR Review
Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.0.19.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.0.19 Context Files Support Auto-detect architecture docs, CLAUDE.md, AGENTS.md, SOUL.md, MEMORY.md, README as review context User can specify custom context files via context_files input (comma-separated paths) Smart budget: context files only fetched when diff < 70K chars (15K budget for context) LLM receives context in <context> block alongside the diff for better-informed reviews Inline Comments for OpenCode Engine OpenCode engine now posts inline resolvable review comments via post-processing step post_inline.py extracts issues JSON from OpenCode review and posts as PR review comments Summary comment updated to remove duplicate key issues section Improvements Only warn for user-specified context paths, not auto-detect Diff size check for OpenCode engine before fetching context files
July 1, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.87.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 1, 2026
Suppress Ratchet
Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: initial Suppress Ratchet action — gate linter suppressions (Python + TS) (7d9b6e0)
July 1, 2026
Themis PR Gate
Version updated for https://github.com/Pheoxy/themis to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Themis v1.0.2 is a patch release for GitHub Marketplace publication metadata.
Changed GitHub Action Marketplace display name changed from Themis to Themis PR Gate so it satisfies GitHub Marketplace’s global action-name uniqueness requirement. Stable GitHub Action examples now reference Pheoxy/themis@v1.0.2. Documentation now explains why the Marketplace display name differs from the project name. Verification Completed before tagging:
July 1, 2026
Polygraph MCP gate
Version updated for https://github.com/polygraphso/litmus to version litmus-v0.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor release shipping two changes from a false-positive review of the harness:
#78 fix(c02) — the C-02 egress D rationale is now actionable: it names the undeclared host(s) and points authors at polygraph.egress, and the CLI itemizes them. Messaging only — every server’s letter grade is byte-identical. #79 feat(sandbox) — pypi/uvx MCP servers are now gradeable under the Docker sandbox. They stage wheels-only into a venv (no target code runs during staging; fails closed on sdist), resolve offline, and launch with the venv python. Both the connect and C-02 egress paths support pypi; gVisor runtime parity preserved. methodologyVersion is unchanged (litmus-v10) — a pypi server is graded by the same rubric as an npm one.
July 1, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.6.34.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed When the agentic selection call fails (429, timeout, unparseable output), Outrider’s fallback picks the highest-relevance candidate. Ties on relevance were previously broken by list position — Python’s max() returns the first element at the max value.
July 1, 2026
MaintainerOps AI
Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.11 npm Provenance Metadata Repair MaintainerOps AI v0.1.11 is a publishing metadata repair release after v0.1.10 reached npm Trusted Publishing but failed provenance validation.
Fix Adds package.json repository.url with https://github.com/rtonf/maintainerops-ai. Keeps the npm Trusted Publishing workflow tokenless and provenance-backed. Preserves the v0.1.10 model-backed eval, label normalization, and release workflow changes. Verification Plan npm run verify GitHub PR checks and post-merge CodeQL Publish GitHub Release v0.1.11 Confirm the npm Trusted Publishing workflow publishes maintainerops-ai@0.1.11 Verify: npm view maintainerops-ai version dist-tags time --json npm exec --yes --package maintainerops-ai@latest -- maintainerops --help
July 1, 2026
RsMetaCheck
Version updated for https://github.com/SoftwareUnderstanding/rs-metacheck-action to version 0.3.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed entry point typo to use the latest RSMetaCheck version by @francoto
July 1, 2026
danger-ruby-action
Version updated for https://github.com/tdrk18/danger-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed New Inputs Added 6 new inputs to expose missing Danger CLI options:
fail-on-errors — Always fail the build when Danger reports errors (--fail-on-errors) fail-if-no-pr — Fail the build if no PR is found (--fail-if-no-pr) new-comment — Post a new comment instead of editing the previous one (--new-comment) remove-previous-comments — Remove all previous comments and post a new one (--remove-previous-comments) base — Branch/tag/commit to use as the base of the diff (--base) head — Branch/tag/commit to use as the head of the diff (--head) All new inputs are optional and default to their Danger defaults, so existing workflows are unaffected.
July 1, 2026
Crosspost Action
Version updated for https://github.com/tgagor/action-crosspost to version v1.6.5.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.6.5 (2026-07-01)
July 1, 2026
Polder Drift — Design System Drift Alerts
Version updated for https://github.com/usepolder/drift to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: review findings — shallow-checkout false-new (#8) + hardening by @jongjesse in https://github.com/usepolder/drift/pull/2 test: re-home Carbon/MUI integration tests (vendored fixtures + DS devDeps) by @jongjesse in https://github.com/usepolder/drift/pull/3 chore: repo polish (CodeRabbit config, CONTRIBUTING, badges) by @jongjesse in https://github.com/usepolder/drift/pull/1 Fix glob translation: leading/embedded **/ matches zero or more dirs by @jongjesse in https://github.com/usepolder/drift/pull/4 Fix unit-inconsistent adoption metric: count drifted components, not findings by @jongjesse in https://github.com/usepolder/drift/pull/5 fix: surface comment-post failures instead of swallowing them by @jongjesse in https://github.com/usepolder/drift/pull/6 chore: prep v1 for GitHub Marketplace publish by @jongjesse in https://github.com/usepolder/drift/pull/8 fix: paginate GitHub issue-comment lookup to avoid duplicate comments by @jongjesse in https://github.com/usepolder/drift/pull/7 New Contributors @jongjesse made their first contribution in https://github.com/usepolder/drift/pull/2 Full Changelog: https://github.com/usepolder/drift/commits/v1.0.0
July 1, 2026
RepoScope Security & Compliance Scanner
Version updated for https://github.com/xdun1698/reposcope-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed RepoScope Security & Compliance Scanner v1.0.0 First public release — run RepoScope’s scanner in CI to catch security issues and generate audit-ready compliance evidence on every push and pull request.
What’s included 44 security detectors across 14 languages — hardcoded secrets, SQL injection, XSS, command injection, TLS misconfigs, weak crypto, permissive CORS Inline PR review comments — one per finding with file, line, severity, CWE ID, and fix hint GitHub Check run — PASS/FAIL with a configurable score threshold and annotations on high/critical findings Compliance report artifact — HTML report mapping findings to OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 Configurable build gate — fail-on severity and score threshold Inline suppression via reposcope-ignore comments Setup instructions and all inputs/outputs are in the README.
July 1, 2026
gmc — Google Merchant Center CLI
Version updated for https://github.com/yasserstudio/gmc to version v1.0.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed gmc ordertracking — Order Tracking sub-API (ordertracking/v1) Adds gmc ordertracking — the Order Tracking sub-API (accounts.orderTrackingSignals). This was the last remaining GA (v1) Merchant API sub-API, so the stable v1 surface is now fully covered (12 GA sub-APIs).
July 1, 2026
EcoTrace Carbon Gate
Version updated for https://github.com/Zwony/ecotrace to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed EcoTrace v1.4.0 Released: 2026-07-01 Type: Feature Release — 6 new features, 4 bug fixes, zero breaking changes
New Features Pausable Tracking API (pause() / esume()) Pause and resume carbon tracking to isolate your code’s emissions from setup/teardown overhead.
July 1, 2026
HOL Codex Plugin Scanner
Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.355.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.355
July 1, 2026
Holon Solve
Version updated for https://github.com/holon-run/holon to version v0.25.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.25.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release adds a Bing Web Search provider with managed WebSearch tool kept alongside native search, an external trigger token-only storage model with reset-callback API, and trigger revocation on agent stop. It also fixes max_turns counting, coerce_string JSON-string parsing for tool arguments, callback_base_url/advertise_url decoupling, and skill install for non-flat catalog layouts. The memory indexer is redesigned as a single daemon with outbox cleanup, and SQLite connection init gains PRAGMA tuning for better performance.
July 1, 2026
lgtmaybe
Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.1 (2026-07-01) Documentation streamline install + local-model guides (#160) (6425ad3)
July 1, 2026
Totem Shield
Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.86.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.
July 1, 2026
agent-bom Scan
Version updated for https://github.com/msaad00/agent-bom to version v0.91.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(release): 0.90.1 hygiene — soften SCA framing, fix stale pins, README callouts by @msaad00 in https://github.com/msaad00/agent-bom/pull/3314 fix(sca): honor NVD CPE inclusive/exclusive version bounds exactly by @msaad00 in https://github.com/msaad00/agent-bom/pull/3315 fix(output): surface match_confidence_tier across SARIF, JSON, HTML by @msaad00 in https://github.com/msaad00/agent-bom/pull/3317 fix(release): harden post-0.90 audit findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3316 fix(output): carry match_confidence_tier on the JSON blast_radius rollup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3319 fix(ui): fail fast offline and polish README how-it-works diagram by @msaad00 in https://github.com/msaad00/agent-bom/pull/3318 fix(sca): make NVD capped sync ingest its unsynced tail across runs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3320 fix(version): correct post-release regex and prerelease ordering in version compare by @msaad00 in https://github.com/msaad00/agent-bom/pull/3330 fix(graph): keep cross-page attack paths in filtered /graph by @msaad00 in https://github.com/msaad00/agent-bom/pull/3321 fix(cli): fail-close –fail-on-severity on unknown/none findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3322 fix(mcp): emit canonical OWASP codes from tool-abuse rules by @msaad00 in https://github.com/msaad00/agent-bom/pull/3323 fix(sarif): de-duplicate cloud CIS failures in SARIF output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3324 fix(inventory): keep distinct MCP servers distinct across identity, enrichment, and Cortex audit by @msaad00 in https://github.com/msaad00/agent-bom/pull/3325 chore(deps): combine UI dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3337 fix(model-scan): close pickle-scan size gate and memo evasion by @msaad00 in https://github.com/msaad00/agent-bom/pull/3326 fix(version): honor tagged bounds for Go pseudo-versions by @msaad00 in https://github.com/msaad00/agent-bom/pull/3327 fix(image): warn on legacy rpmdb instead of silent zero coverage by @msaad00 in https://github.com/msaad00/agent-bom/pull/3328 fix(mcp): block SSRF in repo scan and offload clone off the event loop by @msaad00 in https://github.com/msaad00/agent-bom/pull/3329 feat(ui): design-system foundation — Collapsible, Card/Section, entity icons, vendor logos, state primitives by @msaad00 in https://github.com/msaad00/agent-bom/pull/3338 fix(sca): harden OSV/NVD/KEV/GHSA sync + SQLite concurrency (availability) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3339 feat(ui): real connections experience — vendor logos + connector cards wired to backend by @msaad00 in https://github.com/msaad00/agent-bom/pull/3340 fix(api): bind audit tenant server-side, harden rate-limit identity + global ceiling by @msaad00 in https://github.com/msaad00/agent-bom/pull/3341 fix(output): dedup CycloneDX components + scope finding id by package by @msaad00 in https://github.com/msaad00/agent-bom/pull/3342 fix(ui): align connections screenshot spec with redesigned headings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3344 feat: capability-depth — reachability→CVE, perf, identity owner-binding, FinOps rates, SBOM attestation/SPDX2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3346 feat(ui): declutter, capability-driven IA, interaction-state fixes, real trust stack by @msaad00 in https://github.com/msaad00/agent-bom/pull/3347 feat(gateway): OAuth 2.1 AS conformance + inline A2A mutual-auth enforcement + per-tool-call scope/DLP by @msaad00 in https://github.com/msaad00/agent-bom/pull/3348 chore(release): v0.91.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3349 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.90.0...v0.91.0
July 1, 2026
Codeowners Plus
Version updated for https://github.com/multimediallc/codeowners-plus to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v1.9.1 by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/133 Add gomodUpdateImportPaths to renovate config by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/135 dev: Update module github.com/google/go-github/v85 to v86 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/125 Fully support sha pinning + remove docker from runtime. by @Icantjuddle in https://github.com/multimediallc/codeowners-plus/pull/143 Fix goreleaser trigger by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/146 ci: trigger goreleaser on tag push, create draft release by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/148 fix: action path has infixed ./ for local action runs by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/149 Bump the gomod group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/151 dev: Update actions/checkout action to v7 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/153 dev: Update golangci/golangci-lint-action action to v9.2.1 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/140 Example workflow fixes by @kolayne in https://github.com/multimediallc/codeowners-plus/pull/150 Add the config.disable_review_status_comments config option by @kolayne in https://github.com/multimediallc/codeowners-plus/pull/160 Bump the github-actions group with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/156 Bump the gomod group with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/157 fix: Make sort order deterministic by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/162 New Contributors @kolayne made their first contribution in https://github.com/multimediallc/codeowners-plus/pull/150 Full Changelog: https://github.com/multimediallc/codeowners-plus/compare/v1.9.1...v1.10.0
July 1, 2026
AI Cost Receipt
Version updated for https://github.com/noah-thing/receipt to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Builds on 0.4.0’s session health with automation, history, and a reviewer-facing note.
receipt guard — a Claude Code hook entrypoint. Stays silent until a session crosses your gate, then prints the single most important move where the agent sees it. With --notify it exits 2 so Claude Code feeds the nudge back to the model — strongest on the PreCompact hook, right before lossy auto-compaction. receipt health --json / --quiet --gate — machine-readable output and severity exit codes (0 / 10 watch / 20 degrading / 30 critical) for hooks and CI. receipt health --all — scores every past session and learns your personal pattern (“you tend to drift around turn ~12; X% of sessions compacted too late”). Context tax — shows how much of a session is just re-sending itself (the quadratic cost behind both rising spend and fading quality). PR-comment health note — a collapsed, reviewer-facing <details> block when the work ran under degrading conditions; silent otherwise; opt out with "health": false. It never claims the code is wrong — only points to where to look. Honest constraint: the token-only ledger cannot detect redundant file reads, identical-command loops, or semantic issues (hallucinations, drift) — those need data Receipt deliberately never stores. Features only ever flag “conditions correlated with drift,” documented in docs/SESSION-HEALTH.md.
July 1, 2026
Run AER Tests
Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.3
Add Downloaded aer To Integrated Terminal PATH
Publish Platform Events Created By Flows And Stamp Generated-Code Line Numbers
Fix Flow Line-Info Backfill And Skip Time-Based Scheduled Paths In Tests
July 1, 2026
Postman API Onboarding
Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: skip+warn built-in tests without api key + access-token-primary docs by @jaredboynton in https://github.com/postman-cs/postman-api-onboarding-action/pull/56 Full Changelog: https://github.com/postman-cs/postman-api-onboarding-action/compare/v1...v2
July 1, 2026
Postman Onboarding AWS Spec Discovery
Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13 chore(deps): bump the npm-minor-patch group across 1 directory with 21 updates by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/10 chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/9 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/12 feat: optional access-token telemetry account_type by @jaredboynton in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/23 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13 Full Changelog: https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v1...v2
July 1, 2026
Postman Onboarding Workspace Bootstrap
Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/48 chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/44 chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/46 chore: add workflow_dispatch trigger to CI workflow by @andrewpostymt in https://github.com/postman-cs/postman-bootstrap-action/pull/36 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/59 feat: sync additional local collections by @andrewpostymt in https://github.com/postman-cs/postman-bootstrap-action/pull/61 feat: access-token gateway migration + EC v3 multiprotocol collections by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/64 Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v1...v2
July 1, 2026
Postman Onboarding Insights Linking
Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/26 chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/24 chore(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/23 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/25 fix: implement support for xray key matching by @hiqbal-postman in https://github.com/postman-cs/postman-insights-onboarding-action/pull/10 feat: thread access-token re-mint through Bifrost catalog client by @jaredboynton in https://github.com/postman-cs/postman-insights-onboarding-action/pull/36 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-insights-onboarding-action/pull/26 @hiqbal-postman made their first contribution in https://github.com/postman-cs/postman-insights-onboarding-action/pull/10 Full Changelog: https://github.com/postman-cs/postman-insights-onboarding-action/compare/v1...v2
July 1, 2026
Postman Onboarding Repo Sync
Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-repo-sync-action/pull/40 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-repo-sync-action/pull/39 fix: pass CI_ENVIRONMENT key to postman collection run env-var flag by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/49 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/54 feat: add Azure DevOps repo sync support by @andrewpostymt in https://github.com/postman-cs/postman-repo-sync-action/pull/58 feat: access-token gateway routing + @postman v3 converter cutover by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/61 New Contributors @andrewpostymt made their first contribution in https://github.com/postman-cs/postman-repo-sync-action/pull/58 Full Changelog: https://github.com/postman-cs/postman-repo-sync-action/compare/v1...v2
July 1, 2026
Postman Onboarding Service Token
Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-resolve-service-token-action/pull/10 chore(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-resolve-service-token-action/pull/9 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-resolve-service-token-action/pull/17 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-resolve-service-token-action/pull/10 Full Changelog: https://github.com/postman-cs/postman-resolve-service-token-action/compare/v1...v2
July 1, 2026
Postman Onboarding Smoke Flow
Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-smoke-flow-action/pull/16 build(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-smoke-flow-action/pull/15 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-smoke-flow-action/pull/23 feat: access-token-only Smoke reshape via v3 gateway by @jaredboynton in https://github.com/postman-cs/postman-smoke-flow-action/pull/28 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-smoke-flow-action/pull/16 Full Changelog: https://github.com/postman-cs/postman-smoke-flow-action/compare/v1...v2.0.0
July 1, 2026
Remyx Outrider
Version updated for https://github.com/remyxai/outrider to version v1.6.31.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The self-review call now honors the claude-timeout workflow input — completing the per-stage timeout consolidation begun in v1.6.28 (preflight), v1.6.29 (audit), v1.6.30 (selection). After this release, claude-timeout is the single budget knob across every Claude-Code stage in the chain.
July 1, 2026
rumdl-action
Version updated for https://github.com/rvben/rumdl to version v0.2.27.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed MD077: detect latent list markers past an unstable heading (05d273e) MD013: keep reference-style links atomic when reflowing (a991a71) Downloads File Platform Checksum rumdl-v0.2.27-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.27-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.27-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.27-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.27-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.27-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.27-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.
July 1, 2026
Docker Compose Cache
Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.15.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci: fail summary jobs when upstream jobs do not succeed by @seijikohara in https://github.com/seijikohara/docker-compose-cache-action/pull/301 chore(deps): update actions/checkout action to v7 by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/297 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/302 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.14...v1.8.15
July 1, 2026
Satellite Deploy
Version updated for https://github.com/snakenet-org/satellite-deploy to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial first release of GitHub action for the Satellite Auto-Deployment feature
July 1, 2026
Difftron Delta Coverage Gate
Version updated for https://github.com/swantron/difftron to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release.
Fail a pull request when newly changed lines aren’t tested — language-agnostic delta/patch coverage for LCOV, Cobertura, and Go coverage, in a few lines of YAML.
Composite Action, builds from source — no external binary to trust
July 1, 2026
Release Uclusion
Version updated for https://github.com/Uclusion/release-job to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed T-all-2238 Mark a job deployed only when its latest commits are on the env (ce28b48) fix: move to node 24.x (497b508) fix: link doc (92f76e8) Merge remote-tracking branch ‘origin/main’ (bcadebe) fix: space in view name (3677e82) Update README.md (e9f6d6c) feat: label releases (80fdfc6) feat: label releases (24faaeb) feat: label releases (1274acb) feat: label releases - untested (bed25f2)
July 1, 2026
Update Uclusion
Version updated for https://github.com/Uclusion/update-job to version v1.1.2.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19) T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb) fix: Only extract job ids. (340d9bb) fix: move to node 24.x (a19c034) fix: move to node 24.x (ab6d493) fix: link doc (c83286a) fix: space in view name (ff4ac90) fix: space in view name (d0c570f) fix: urlencode (f66608d) fix: cleanup (93a64c0)
July 1, 2026
MIU PR Review
Version updated for https://github.com/vanducng/miu-cr to version v0.81.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.81.0 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.81.0 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.81.0 GitHub Action:
July 1, 2026
Setup vp
Version updated for https://github.com/voidzero-dev/setup-vp to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): update dependency vite-plus to v0.1.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/78 chore(deps): update vite+ to v0.1.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/79 chore(deps): update github actions to v3.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/80 test: add Node 20 to node-version matrix (expected red until Vite+ supports it) by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/84 chore(deps): upgrade vite-plus to 0.2.1 by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/85 docs: update shared agent guidance by @jong-kyung in https://github.com/voidzero-dev/setup-vp/pull/89 chore: switch input schemas to zod mini by @jong-kyung in https://github.com/voidzero-dev/setup-vp/pull/98 chore(deps): update dependency @actions/cache to v6.1.0 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/86 chore(deps): update pnpm to v11.9.0 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/99 fix: install pkg.pr.new preview builds via VP_PR_VERSION by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/100 New Contributors @jong-kyung made their first contribution in https://github.com/voidzero-dev/setup-vp/pull/89 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.12.0...v1.13.0
July 1, 2026
docs-version-deploy
Version updated for https://github.com/yukiakai212/docs-version-deploy to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/yukiakai212/docs-version-deploy/compare/v1...v2