@actions/github

npm

Is @actions/github safe to use?

Based on the latest brin safety scan, no vulnerabilities or threats were detected for @actions/github v9.0.0. Trust score: 85/100. No known CVE vulnerabilities, no detected threat patterns, and no suspicious capabilities identified. This is an automated, point-in-time assessment.

Install (safety-checked)

@actions/github Passed Security Checks

No security concerns detected

clean
CVEs

0

Threats

0

Install Scripts

0

No Concerns Detected

No security concerns detected in the latest brin assessment. This is an automated, point-in-time evaluation — security posture may change.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

@actions/github Capabilities & Permissions

What @actions/github can access when installed. Review these capabilities before using with AI agents like Cursor, Claude Code, or Codex.

Network Access

This package makes network requests.

api.github.comgithub.com
Protocols: https

Environment Variables

Accesses the following environment variables.

GITHUB_ACTIONGITHUB_ACTORGITHUB_API_URLGITHUB_EVENT_NAMEGITHUB_EVENT_PATHGITHUB_GRAPHQL_URLGITHUB_JOBGITHUB_REFGITHUB_REPOSITORYGITHUB_RUN_ATTEMPT+5 more

AGENTS.md for @actions/github

Good instructions lead to good results. brin adds @actions/github documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

@actions/github Documentation & Source Code

For the full @actions/github README, API documentation, and source code, visit the official package registry.

Frequently asked questions about @actions/github safety

Weekly Downloads

4.1M

Version

9.0.0

License

MIT

Last Scanned

Jan 31, 2026

Trust Score

85/100·Legitimacy signals, not safety

Capabilities

Network

Connects to: api.github.com, github.com

Environment

Accesses: GITHUB_ACTION, GITHUB_ACTOR, GITHUB_API_URL...

Is @actions/github Safe? | npm Safety Scan - brin