The recent `tj-actions/changed-files` security incident is scary, so we built a mutable-reference scanner that performs a deep scan across branches to identify all third-party GitHub actions used in organization Git projects. The output report can be exported to CSV or JSON (default).
Try it out!