StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

touchlab/ga-update-release-tag

touchlab/ga-update-release-tag

GitHub action to update git tag for a GitHub Release. Used in support of KMMBridge publishing.

2/10
actions-security-demo/script-injection/pkg/build/actions/bump-version

actions-security-demo/script-injection/pkg/build/actions/bump-version

2/10
onekeyhq/actions/build-plist-edit

onekeyhq/actions/build-plist-edit

Github Actions

2/10
Maintained action available
step-security/helm-gh-pages/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/helm-gh-pages/__builder_checkout_dir__/.github/actions/secure-download-artifact

A GitHub Action for publishing Helm charts to Github Pages. Secure drop-in replacement for stefanprodan/helm-gh-pages.

10/10
launchdarkly/rust-server-sdk-evaluation/.github/actions/build-docs

launchdarkly/rust-server-sdk-evaluation/.github/actions/build-docs

Types and eval logic for LaunchDarkly Rust SDKs

6/10
dchourasia/ms-teams-notification

dchourasia/ms-teams-notification

Microsoft Teams Notification from Github Workflow

2/10
coinbase/cdp-sdk/.github/actions/fetch-docs-artifact

coinbase/cdp-sdk/.github/actions/fetch-docs-artifact

Client libraries for managing EVM and Solana wallets while relying on CDP to secure private keys.

6/10
step-security/background-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/background-action/__builder_checkout_dir__/.github/actions/privacy-check

Background commands with log tailing/capture; waits until file/port/socket/http are ready to proceed. Isolates/dedupe errors. Secure drop-in replacement for JarvusInnovations/background-action.

10/10
caffeelake/llvm-project/workflows-main/.github/workflows/release-binaries-save-stage

caffeelake/llvm-project/workflows-main/.github/workflows/release-binaries-save-stage

The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.

2/10
step-security/semver-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/semver-action/__builder_checkout_dir__/.github/actions/privacy-check

GitHub Action to calculate the next release version based on conventional commits. Secure drop-in replacement for ietf-tools/semver-action.

8/10
centml/dynamo/.github/actions/check-vcluster-exists

centml/dynamo/.github/actions/check-vcluster-exists

A Datacenter Scale Distributed Inference Serving Framework

4/10
Maintained action available
zaproxy/action-full-scan

zaproxy/action-full-scan

A GitHub Action for running the ZAP Full scan

7/10
yonasbsd/mise/.github/actions/fetch-token

yonasbsd/mise/.github/actions/fetch-token

dev tools, env vars, task runner

6/10
oracle-actions/setup-java

oracle-actions/setup-java

GitHub Action to download and install Oracle's Java Development Kit builds

6/10
actions-rs/toolchain

actions-rs/toolchain

๐Ÿ› ๏ธ GitHub Action for `rustup` commands

3/10
lfreleng-actions/gerrit-clone-action

lfreleng-actions/gerrit-clone-action

Action to bulk clone (in parallel) an entire Gerrit server repository hierarchy

4/10
Maintained action available
asyncapi/.github/.github/actions/get-node-version-from-package-lock

asyncapi/.github/.github/actions/get-node-version-from-package-lock

Location of all reusable community health files

8/10
pytorch/pytorch/pytorch/.github/actions/ecr-login

pytorch/pytorch/pytorch/.github/actions/ecr-login

Tensors and Dynamic neural networks in Python with strong GPU acceleration

4/10
Maintained action available
step-security/action-shfmt/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/action-shfmt/__builder_checkout_dir__/.github/actions/secure-download-artifact

Run shfmt with reviewdog. Secure drop-in replacement for reviewdog/action-shfmt.

10/10
step-security/create-pull-request/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/create-pull-request/__builder_checkout_dir__/.github/actions/secure-download-artifact

A GitHub action to create a pull request for changes to your repository in the actions workspace. Secure drop-in replacement for peter-evans/create-pull-request.

10/10