Anything you use in a critical path you should control. If you're managing your own fork, nobody will inject bad code except yourself.
Just my 2 cents. Also, the things that github 3rd party actions are doing is usually not that complicated. I mean how many different ways can you publish a docker image or deploy an artifact to S3. Once it works, it either works or doesn't. It's not a programming library where optimizations are created or we fixed a security vulnerability (though I suppose that can come up ).
Sorry minor rant. food for thought.