StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

anchore/workflows/.github/actions/python

anchore/workflows/.github/actions/python

reusable workflows to be used for the oss projects

8/10
yonasbsd/grype/.github/actions/bootstrap

yonasbsd/grype/.github/actions/bootstrap

A vulnerability scanner for container images and filesystems

6/10
yuki0n0/action-appstoreconnect-token

yuki0n0/action-appstoreconnect-token

App Store Connect API token generator.

1/10
dsanders11/project-actions/get-workflow

dsanders11/project-actions/get-workflow

A collection of actions for automating GitHub projects

5/10
Maintained action available
cqlabs/setup-dcm

cqlabs/setup-dcm

GitHub Action to install and setup DCM

2/10
jonathancombs782/bitcoin/.github/actions/configure-environment

jonathancombs782/bitcoin/.github/actions/configure-environment

Bitcoin Core integration/staging tree

6/10
sasobadovinac/pytorch/.github/actions/teardown-xpu

sasobadovinac/pytorch/.github/actions/teardown-xpu

Tensors and Dynamic neural networks in Python with strong GPU acceleration

4/10
Maintained action available
redpanda-data/arrow-rs/.github/actions/setup-builder

redpanda-data/arrow-rs/.github/actions/setup-builder

Official Rust implementation of Apache Arrow

4/10
nvidia/aicr/.github/actions/prep-kind-runner

nvidia/aicr/.github/actions/prep-kind-runner

Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes

7/10
carabiner-dev/actions/install/ampel-bootstrap

carabiner-dev/actions/install/ampel-bootstrap

GiitHub actions for various tools in the Carabiner ecosystems

6/10
christian-korneck/delete-run-artifacts-action

christian-korneck/delete-run-artifacts-action

github action to delete artifacts at the end of a workflow run

2/10
viasat::Git-Viasat-Com-PoC::seceng-vionix-stepsecurity-poc-test/github/docker-setup-buildx-action

viasat::Git-Viasat-Com-PoC::seceng-vionix-stepsecurity-poc-test/github/docker-setup-buildx-action

Mirror from https://github.com/docker/setup-buildx-action

3/10
Maintained action available
touchlab/sample-group-sanity-check

touchlab/sample-group-sanity-check

Github action to do sanity check around org name and group id

2/10
ministryofjustice/opg-github-actions/actions/terraform-version

ministryofjustice/opg-github-actions/actions/terraform-version

OPG shared GitHub composite actions for workflows.: Managed by opg-org-infra & Terraform

6/10
step-security/action-yamllint

step-security/action-yamllint

GitHub Action - Yaml Lint. Secure drop-in replacement for ibiqlik/action-yamllint.

10/10
Maintained by StepSecurity
gurock/trcli-action

gurock/trcli-action

CI/CD integration

3/10
devantler-tech/ksail/.github/actions/restore-mirror-cache

devantler-tech/ksail/.github/actions/restore-mirror-cache

All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.

3/10
Maintained action available
octodemo/pull-request-review-action

octodemo/pull-request-review-action

3/10
coveooss/terraform/.github/actions/equivalence-test

coveooss/terraform/.github/actions/equivalence-test

Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.

0/10
openzeppelin/openzeppelin-contracts/.github/actions/storage-layout

openzeppelin/openzeppelin-contracts/.github/actions/storage-layout

OpenZeppelin Contracts is a library for secure smart contract development.

6/10