Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
gitea.com/gitea/act
This is a custom fork of nektos/act, for the purpose of serving act_runner.
It cannot be used as command line tool anymore, but only as a library.
It's a soft fork, which means that it will tracking the latest release of nektos/act.
Branches:
main
: default branch, contains custom changes, based on the latest release(not the latest of the master branch) of nektos/act.nektos/master
: mirror for the master branch of nektos/act.Tags:
nektos/vX.Y.Z
: mirror for vX.Y.Z
of nektos/act.vX.YZ.*
: based on nektos/vX.Y.Z
, contains custom changes.
nektos/v0.2.23
-> v0.223.*
nektos/v0.3.1
-> v0.301.*
, not v0.31.*
nektos/v0.10.1
-> v0.1001.*
, not v0.101.*
nektos/v0.3.100
-> not v0.3100.*
"Think globally,
act
locally"
Run your GitHub Actions locally! Why would you want to do this? Two reasons:
.github/workflows/
files (or for any changes to embedded GitHub actions), you can use act
to run the actions locally. The environment variables and filesystem are all configured to match what GitHub provides.act
, you can use the GitHub Actions defined in your .github/workflows/
to replace your Makefile
!When you run act
it reads in your GitHub Actions from .github/workflows/
and determines the set of actions that need to be run. It uses the Docker API to either pull or build the necessary images, as defined in your workflow files and finally determines the execution path based on the dependencies that were defined. Once it has the execution path, it then uses the Docker API to run containers for each action based on the images prepared earlier. The environment variables and filesystem are all configured to match what GitHub provides.
Let's see it in action with a sample repo!
Please look at the act user guide for more documentation.
Need help? Ask on Gitter!
Want to contribute to act? Awesome! Check out the contributing guidelines to get involved.
git clone git@github.com:nektos/act.git
make test
make install
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.