StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

runs-on/cache/restore

runs-on/cache/restore

Shockingly faster GitHub Action cache with S3 backend

5/10
Maintained action available
homebrew/actions/bump-formulae

homebrew/actions/bump-formulae

๐Ÿš€ Homebrew's GitHub Actions

7/10
accenture/autofixture.xunit2.automock/.github/actions/materialize-signing-key

accenture/autofixture.xunit2.automock/.github/actions/materialize-signing-key

Autofixture auto-mocking for XUnit2 using a mocking library of your choice.

8/10
ministryofjustice/laa-submit-a-bulk-claim/.github/actions/get_release_name

ministryofjustice/laa-submit-a-bulk-claim/.github/actions/get_release_name

Web application for bulk upload of claims data

8/10
kong/slsa-github-generator/.github/actions/image

kong/slsa-github-generator/.github/actions/image

Language-agnostic SLSA provenance generation for Github Actions

3/10
harekrishnarai/flowlyt

harekrishnarai/flowlyt

Flowlyt is a security analyzer that scans GitHub Actions workflows to detect malicious patterns, misconfigurations, and secrets exposure, helping enforce secure CI/CD practices.

6/10
thatisuday/go-cross-build

thatisuday/go-cross-build

GitHub Action to build Go (Golang) modules.

2/10
celo-org/social-connect/.github/actions/sync-workspace

celo-org/social-connect/.github/actions/sync-workspace

Protocol mapping social identifiers to blockchain addresses

5/10
Maintained action available
ansible-community/ansible-test-gh-action

ansible-community/ansible-test-gh-action

A composite GitHub Action encapsulating the GitHub Actions CI/CD workflows setup necessary for testing Ansible collection repositories on GitHub

6/10
agenthunt/conventional-commit-checker-action

agenthunt/conventional-commit-checker-action

1/10
nvidia/nemo/send-slack-alert/.github/actions/send-slack-alert

nvidia/nemo/send-slack-alert/.github/actions/send-slack-alert

A scalable generative AI framework built for researchers and developers working on Large Language Models, Multimodal, and Speech AI (Automatic Speech Recognition and Text-to-Speech)

5/10
Maintained action available
grafana/grafana-aws-sdk/actions/commands

grafana/grafana-aws-sdk/actions/commands

Common AWS configs for plugins

7/10
sonatype/actions/fetch-sbom

sonatype/actions/fetch-sbom

Public repository to keep Sonatype's GitHub Actions.

3/10
Maintained action available
hashicorp/actions-packaging-linux

hashicorp/actions-packaging-linux

Public GitHub Actions

6/10
codium-ai/pr-agent

codium-ai/pr-agent

๐Ÿš€ PR Agent: The Original Open-Source PR Reviewer. This project It is not the Qodo free tier.

7/10
vampire/setup-wsl

vampire/setup-wsl

A GitHub action to install and setup a Linux distribution for the Windows Subsystem for Linux (WSL)

5/10
Maintained action available
grafana/mimir-prometheus/.github/promci/actions/publish_main

grafana/mimir-prometheus/.github/promci/actions/publish_main

7/10
ctdiscordshared-lab/newrelic-quickstarts/.github/actions/add-commit-status

ctdiscordshared-lab/newrelic-quickstarts/.github/actions/add-commit-status

New Relic One quickstarts help accelerate your New Relic journey by providing immediate value for your specific use cases.

2/10
credebl/mediator-agent/.github/actions/image

credebl/mediator-agent/.github/actions/image

An easy to set-up Aries and DIDComm v1 mediator built on Aries Framework JavaScript.

3/10
step-security/dummy-imposter-commit-action

step-security/dummy-imposter-commit-action

A harmless GitHub Action designed to show detection of actions with imposter commit

7/10