







Enhance your workflow with extensions
Tools from the community and partners to simplify tasks and automate processes
Code Scanning Ready actions
MegaLinter
ActionCombine all available linters to automatically validate your sources without configuration
Scan your project for AI agent security risks. Detects secrets, misconfigurations, and generates a tailored security config
mobsfscan
Actionmobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code
Run the aislop quality gate on AI-assisted code (scan + fail CI below threshold from .aislop/config.yml)
flawfinder_scan
ActionExecute Flawfinder to scan source code for vulnerabilities
Feluda License Scanner
ActionScan project dependencies for restrictive and incompatible licenses
mcpsnoop
ActionFail CI on what an MCP server actually did on the wire, and file every finding as a code scanning alert
is-my-node-vulnerable
Actionchecks if your Node.js installation is vulnerable to known security vulnerabilities
Qodana Scan
ActionScan your projects with Qodana on GitHub. Docs: https://jb.gg/qodana-github-action
PySentry Security Audit
ActionAudit Python dependencies for known vulnerabilities and upload SARIF results to GitHub Code Scanning
security-devops-action
ActionRun security analyzers
Code-Pathfinder
ActionSecurity scanning with Code Pathfinder - open source, type-aware SAST with cross-file dataflow analysis
ghascompliance
Actionghascompliance
Runs Semgrep with all rules from semgrep-rules-manager
KeyHog Secret Scanner
ActionScan a path for secrets, keep a report, and fail on findings by default
PSRule
ActionRun rules in a GitHub repository
Secure your AI supply chain. Scans Models, Notebooks, and RAG documents for malware, secrets, and PII
AIsbom Security Scanner
ActionAn AI Supply Chain security tool that that detects Pickle bombs and generates CycloneDX SBOMs for ML models
Container Scan
ActionCheck for vulnerabilities in your container image
Scans your code for violations using Salesforce Code Analyzer, uploads results as an artifact, and creates a job summary