StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

armbian/build

armbian/build

The official build framework for the Armbian Linux distribution. This repository contains the complete toolchain and scripts required to compile custom OS images from source, including kernel configuration, U-Boot handling, and board-specific tweaks for various ARM and ARM64 single-board computers.

8/10
step-security/hide-comment-action

step-security/hide-comment-action

Action to hide (minimize) comments in pull request. Secure drop-in replacement for int128/hide-comment-action.

10/10
Maintained by StepSecurity
contentful/create-contentful-app/.github/actions/public-layout.tsx

contentful/create-contentful-app/.github/actions/public-layout.tsx

Bootstrap a Contentful App

6/10
step-security/ansible-galaxy-action/__builder_checkout_dir__/.github/actions/wp-content/uploads/2017/10/relish-video-production.png

step-security/ansible-galaxy-action/__builder_checkout_dir__/.github/actions/wp-content/uploads/2017/10/relish-video-production.png

This Action will import ansible roles on galaxy-ng. Secure drop-in replacement for ansible-actions/ansible-galaxy-action.

10/10
tomasreyes/node/node/.github/actions/install-clang

tomasreyes/node/node/.github/actions/install-clang

Node.js JavaScript runtime โœจ๐Ÿข๐Ÿš€โœจ

4/10
Maintained action available
asdf-vm/actions/plugins-add

asdf-vm/actions/plugins-add

GitHub Actions for the asdf version manager

4/10
step-security/action-read-yaml/__builder_checkout_dir__/.github/actions/privacy-check

step-security/action-read-yaml/__builder_checkout_dir__/.github/actions/privacy-check

Custom github action used to read yaml files, supporting multiple keys and variable replacements. Secure drop-in replacement for pietrobolcato/action-read-yaml.

10/10
sonarsource/sonar-go/.actions/config-gradle

sonarsource/sonar-go/.actions/config-gradle

Go Analyzer

6/10
prometheus/promci-artifacts/restore

prometheus/promci-artifacts/restore

GitHub Actions for artifact persistence between jobs

6/10
sonarsource/ci-github-actions/promote

sonarsource/ci-github-actions/promote

CI/CD GitHub Actions

6/10
burningalchemist/action-gh-nfpm

burningalchemist/action-gh-nfpm

nFPM Packager action

2/10
rapidsai/sccache/.github/actions/artifact_failure

rapidsai/sccache/.github/actions/artifact_failure

Sccache is a ccache-like tool. It is used as a compiler wrapper and avoids compilation when possible. Sccache has the capability to utilize caching in remote storage environments, including various cloud storage options, or alternatively, in local storage.

5/10
Maintained action available
tomhjp/gh-action-jira-comment

tomhjp/gh-action-jira-comment

Add a comment to a Jira issue using GitHub actions

3/10
intheclouddan/publish-vscode-extension

intheclouddan/publish-vscode-extension

GitHub action to publish your VS Code Extension to the Open VSX Registry or Visual Studio Marketplace.

2/10
zephyrproject-rtos/action-first-interaction

zephyrproject-rtos/action-first-interaction

An action for filtering pull requests and issues from first-time contributors

4/10
pozetroninc/github-action-get-latest-release

pozetroninc/github-action-get-latest-release

A Github action to get the latest release from another repository.

3/10
nvidia/kata-containers/.github/cargo-deny-composite-action

nvidia/kata-containers/.github/cargo-deny-composite-action

Kata containers is an implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs.

2/10
yonasbsd/opendal/.github/actions/fuzz_test

yonasbsd/opendal/.github/actions/fuzz_test

Apache OpenDAL: access data freely.

3/10
Maintained action available
kong/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact

kong/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact

Language-agnostic SLSA provenance generation for Github Actions

3/10
ledgerhq/ledger-live/tools/actions/composites/cache/download

ledgerhq/ledger-live/tools/actions/composites/cache/download

Mono-repository for packages related to Ledger Live and its JavaScript ecosystem.

4/10
Maintained action available