StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

egibs/actions/melange-build

egibs/actions/melange-build

A collection of reusable Github Actions workflows.

7/10
pytorch/torchft/test-infra/.github/actions/setup-nvidia

pytorch/torchft/test-infra/.github/actions/setup-nvidia

Fault tolerance for PyTorch (HSDP, LocalSGD, DiLoCo, Streaming DiLoCo)

4/10
chains-project/dirty-waters-action

chains-project/dirty-waters-action

Break the build if your supply chain is dirty

3/10
nvidia/cuda-python/.github/actions/fetch_ctk

nvidia/cuda-python/.github/actions/fetch_ctk

CUDA Python: Performance meets Productivity

6/10
myrotvorets/composite-actions/node-run-script

myrotvorets/composite-actions/node-run-script

Composite actions used by our workflows

3/10
osbuild/pr-best-practices

osbuild/pr-best-practices

Check PRs against our best practices ๐ŸŒŸ

3/10
adrise/matter-casting/.github/actions/dynamic

adrise/matter-casting/.github/actions/dynamic

Matter (formerly Project CHIP) creates more connections between more objects, simplifying development for manufacturers and increasing compatibility for consumers, guided by the Connectivity Standards Alliance.

5/10
Maintained action available
launchdarkly/go-sdk-events/.github/actions/coverage

launchdarkly/go-sdk-events/.github/actions/coverage

Go SDK analytics events support code

4/10
Maintained action available
kenyonj/mark-ready-when-ready

kenyonj/mark-ready-when-ready

GitHub Action that automatically marks a draft PR as ready for review when all required checks pass

4/10
packagist/conductor-github-action

packagist/conductor-github-action

GitHub Action to integrate Private Packagist Conductor with your CI

6/10
mamba-org/provision-with-micromamba

mamba-org/provision-with-micromamba

[DEPRECATED] Use setup-micromamba instead

3/10
step-security/android-emulator-runner

step-security/android-emulator-runner

A GitHub Action for installing, configuring and running hardware-accelerated Android Emulators on macOS virtual machines. Secure drop-in replacement for reactivecircus/android-emulator-runner.

10/10
Maintained by StepSecurity
salehhashemi1992/ai-code-guard

salehhashemi1992/ai-code-guard

Automatically reviews code changes in pull requests using OpenAI models to generate thoughtful suggestions for improving code quality.

3/10
step-security/github-action-aerospike/_next/static/chunks/80627-0608ba4420f1144d.js

step-security/github-action-aerospike/_next/static/chunks/80627-0608ba4420f1144d.js

GitHub Action to set up an Aerospike database. Secure drop-in replacement for reugn/github-action-aerospike.

10/10
entle/action-pagerduty-alert

entle/action-pagerduty-alert

2/10
ministryofjustice/laa-manage-your-civil-cases/.github/actions/set_up_app

ministryofjustice/laa-manage-your-civil-cases/.github/actions/set_up_app

A service to centrally manage civil legal aid cases for the Legal Aid Agency

7/10
yonasbsd/affine/.github/actions/setup-version

yonasbsd/affine/.github/actions/setup-version

There can be more than Notion and Miro. AFFiNE is a next-gen knowledge base that brings planning, sorting and creating all together. Privacy first, open-source, customizable and ready to use.

4/10
Maintained action available
argoproj/argo-rollouts/__builder_checkout_dir__/.github/actions/secure-download-artifact

argoproj/argo-rollouts/__builder_checkout_dir__/.github/actions/secure-download-artifact

Progressive Delivery for Kubernetes

5/10
Maintained action available
step-security/trigger-workflow-and-wait/__builder_checkout_dir__/.github/actions/fill

step-security/trigger-workflow-and-wait/__builder_checkout_dir__/.github/actions/fill

Trigger a workflow in another (or same) repository and wait for the job to finish. Secure drop-in replacement for convictional/trigger-workflow-and-wait.

10/10
asymmetric-research/clusterfuzz-fuzzbot-builder/assets/brand/step-security-full-logo.svg

asymmetric-research/clusterfuzz-fuzzbot-builder/assets/brand/step-security-full-logo.svg

Build environment matching a FuzzBot running Ubuntu 22.04

2/10