StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

tanker187/node-semver/.github/actions/create-check

tanker187/node-semver/.github/actions/create-check

The semver parser for node (the one npm uses)

6/10
sersoft-gmbh/xcodebuild-action

sersoft-gmbh/xcodebuild-action

A GitHub action that runs xcodebuild

5/10
Maintained action available
step-security/gradle-actions/__builder_checkout_dir__/.github/actions/privacy-check

step-security/gradle-actions/__builder_checkout_dir__/.github/actions/privacy-check

A collection of GitHub Actions to accelerate your Gradle Builds on GitHub. Secure drop-in replacement for gradle/actions.

10/10
step-security/tfclean/__builder_checkout_dir__/.github/actions/privacy-check

step-security/tfclean/__builder_checkout_dir__/.github/actions/privacy-check

tfclean is tool to remove applied moved block, import block, etc. Secure drop-in replacement for takaishi/tfclean.

8/10
step-security/setup-qemu-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/setup-qemu-action/__builder_checkout_dir__/.github/actions/privacy-check

GitHub Action to install QEMU static binaries. Secure drop-in replacement for docker/setup-qemu-action.

8/10
jfagoagas/grafana/actions/has-matching-release-tag

jfagoagas/grafana/actions/has-matching-release-tag

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

2/10
ministryofjustice/github-actions/clean-actions-runner

ministryofjustice/github-actions/clean-actions-runner

A collection of reusable GitHub Actions for the Ministry of Justice, designed to streamline and enhance workflows across our projects. โ€ข This repository is defined and managed in Terraform

6/10
ruby/setup-ruby

ruby/setup-ruby

An action to download a prebuilt Ruby and add it to the PATH in 5 seconds

6/10
anz-bank/vscode-sysl/.github/action/github-tag-action

anz-bank/vscode-sysl/.github/action/github-tag-action

VS Code extension for SYSL Language

2/10
ianlewis/todo-issue-reopener

ianlewis/todo-issue-reopener

Reopen issues that are still referenced by TODOs

5/10
Maintained action available
devantler-tech/ksail/.github/actions/warm-mirror-cache

devantler-tech/ksail/.github/actions/warm-mirror-cache

All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.

5/10
Maintained action available
politicalsphere/ci/.github/actions/build

politicalsphere/ci/.github/actions/build

CI/CD pipelines and GitHub Actions for Political Sphere

2/10
vbem/k8s-port-forward

vbem/k8s-port-forward

An action forward local ports to workloads in Kubernetes.

3/10
joschi/setup-jdk

joschi/setup-jdk

(DEPRECATED) Set up your GitHub Actions workflow with a specific version of AdoptOpenJDK

2/10
hashicorp/terraform-github-actions/init

hashicorp/terraform-github-actions/init

Terraform GitHub Actions

5/10
prisma-cloud-shiftleft/iac-scan-action

prisma-cloud-shiftleft/iac-scan-action

Prisma Cloud IaC Scan GitHub Action

2/10
benjlevesque/short-sha

benjlevesque/short-sha

Github Action to shorten the git SHA1 and make it accessible in outputs

6/10
snyk/actions/golang

snyk/actions/golang

A set of GitHub actions for checking your projects for vulnerabilities.

5/10
austenstone/merge-queue-demo/.github/actions/create-pr

austenstone/merge-queue-demo/.github/actions/create-pr

GitHub Merge Queue demo

3/10
pravipati-sandbox/codeql-action/autobuild

pravipati-sandbox/codeql-action/autobuild

Actions for running CodeQL analysis

2/10