StepSecurity Logo
Community Tier

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

octodemo/philips-actions-workshop/.github/actions/custom-js-action

octodemo/philips-actions-workshop/.github/actions/custom-js-action

0/10
actions/runner

actions/runner

The Runner for GitHub Actions :rocket:

10/10
scribe-security/action-slsa

scribe-security/action-slsa

Collect, Create and Store SLSA provenance evidence

3/10
stCarolas/setup-maven

stCarolas/setup-maven

Set up your GitHub Actions workflow with a specific version of Apache Maven

4/10
mattnotmitt/doxygen-action

mattnotmitt/doxygen-action

GitHub Action for generating Doxygen documentation for your projects.

5/10
actionshub/chef-delivery

actionshub/chef-delivery

Repository for the chef-delivery-action Github Action

5/10
elastic/apm-agent-java/.github/workflows/stash

elastic/apm-agent-java/.github/workflows/stash

8/10
JuliaRegistries/Registrator.jl

JuliaRegistries/Registrator.jl

Julia package registration bot

4/10
seemethere/download-artifact-s3

seemethere/download-artifact-s3

2/10
docker/setup-qemu-action

docker/setup-qemu-action

GitHub Action to install QEMU static binaries

8/10
op5dev/tf-via-pr

op5dev/tf-via-pr

Plan and apply Terraform/OpenTofu via PR automation, using best practices for secure and scalable IaC workflows.

7/10
mheap/github-action-required-labels

mheap/github-action-required-labels

Fail the build if/unless a certain combination of labels are applied to a pull request

3/10
nanasess/setup-chromedriver

nanasess/setup-chromedriver

ChromeDriver for use in GitHub Actions

5/10
peter-evans/create-issue-from-file

peter-evans/create-issue-from-file

A GitHub action to create an issue using content from a file

6/10
coveo/ui-kit/.github/actions/setup-sfdx

coveo/ui-kit/.github/actions/setup-sfdx

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

5/10
hashicorp/ghaction-import-gpg

hashicorp/ghaction-import-gpg

DEPRECATED - GitHub action to import GPG private key

5/10
NuGet/login

NuGet/login

Connect to nuget.org

5/10
asana/push-signed-commits

asana/push-signed-commits

This composite Github Action uses the createCommitOnBranch GraphQL mutation to allow Github Apps to push 'Verified' commits to Github.

3/10
grafana/alloy/_shared-workflows-dockerhub-login/actions/get-vault-secrets

grafana/alloy/_shared-workflows-dockerhub-login/actions/get-vault-secrets

OpenTelemetry Collector distribution with programmable pipelines

8/10
rokroskar/workflow-run-cleanup-action

rokroskar/workflow-run-cleanup-action

Github action to cancel previous running instances of a workflow.

5/10