Skip to content

Enhance your workflow with extensions

Tools from the community and partners to simplify tasks and automate processes

    Code Scanning Ready actions

    Static analysis, dynamic analysis, container scanning, linting, and fuzzing tools that integrate with GitHub Code Scanning SARIF Upload

    Combine all available linters to automatically validate your sources without configuration

    Scan your project for AI agent security risks. Detects secrets, misconfigurations, and generates a tailored security config

    mobsfscan

    Action

    mobsfscan is a SAST that can find insecure code patterns in your Android and iOS source code

    Run the aislop quality gate on AI-assisted code (scan + fail CI below threshold from .aislop/config.yml)

    Execute Flawfinder to scan source code for vulnerabilities

    Scan project dependencies for restrictive and incompatible licenses

    mcpsnoop

    Action

    Fail CI on what an MCP server actually did on the wire, and file every finding as a code scanning alert

    checks if your Node.js installation is vulnerable to known security vulnerabilities

    Scan your projects with Qodana on GitHub. Docs: https://jb.gg/qodana-github-action

    Audit Python dependencies for known vulnerabilities and upload SARIF results to GitHub Code Scanning

    image/svg+xml

    Run security analyzers

    Security scanning with Code Pathfinder - open source, type-aware SAST with cross-file dataflow analysis

    ghascompliance

    Runs Semgrep with all rules from semgrep-rules-manager

    Scan a path for secrets, keep a report, and fail on findings by default

    image/svg+xml

    PSRule

    Action

    Run rules in a GitHub repository

    Secure your AI supply chain. Scans Models, Notebooks, and RAG documents for malware, secrets, and PII

    An AI Supply Chain security tool that that detects Pickle bombs and generates CycloneDX SBOMs for ML models

    Check for vulnerabilities in your container image

    Scans your code for violations using Salesforce Code Analyzer, uploads results as an artifact, and creates a job summary