StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/plugin-ci-workflows/actions/plugins/trufflehog

grafana/plugin-ci-workflows/actions/plugins/trufflehog

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

4/10
Maintained action available
grafana/github-sync

grafana/github-sync

โคต๏ธ A GitHub Action for syncing current repository with remote

5/10
aws-actions/aws-codebuild-run-build

aws-actions/aws-codebuild-run-build

Run an AWS CodeBuild project as a step in a GitHub Actions workflow job.

5/10
olegtarasov/get-tag

olegtarasov/get-tag

A GitHub action that gets current tag name and puts it into an environment variable

3/10
cybernop/push-fsh-profiles

cybernop/push-fsh-profiles

3/10
anthonyharrison/sbom4python

anthonyharrison/sbom4python

A tool to generate a SBOM (Software Bill of Materials) for an installed Python module

3/10
Maintained action available
pre-commit/pre-commit-hooks

pre-commit/pre-commit-hooks

Some out-of-the-box hooks for pre-commit

7/10
nvidia/megatron-lm/.github/actions/check-nvidia-sso-membership

nvidia/megatron-lm/.github/actions/check-nvidia-sso-membership

Ongoing research training transformer models at scale

3/10
Maintained action available
aerospike/aerospike-client-go/.github/actions/single-node-sc-cluster

aerospike/aerospike-client-go/.github/actions/single-node-sc-cluster

Aerospike Client Go

5/10
Maintained action available
tomasreyes/kafka/.github/actions/gh-api-approve-run

tomasreyes/kafka/.github/actions/gh-api-approve-run

Mirror of Apache Kafka

3/10
Maintained action available
abatilo/release-info-action

abatilo/release-info-action

Get the latest release of some GitHub repository

4/10
m-s-abeer/update-gha-summary-with-workflow-inputs

m-s-abeer/update-gha-summary-with-workflow-inputs

This A GitHub Action that automatically creates a formatted table of all workflow_dispatch input parameters in your workflow summary.

3/10
checkmarx/dustilock

checkmarx/dustilock

DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.

6/10
minicli/action-contributors

minicli/action-contributors

GitHub Action to dynamically update CONTRIBUTORS file

3/10
ericcornelissen/odgen-action/all

ericcornelissen/odgen-action/all

A GitHub Action for ODGen

4/10
kubernetes-sigs/kubebuilder-release-tools

kubernetes-sigs/kubebuilder-release-tools

Release tooling for KubeBuilder projects.

4/10
dekinderfiets/pr-description-enforcer

dekinderfiets/pr-description-enforcer

2/10
step-security/github-action-aerospike/_next/static/chunks/52206-c3a78c17c6739a35.js

step-security/github-action-aerospike/_next/static/chunks/52206-c3a78c17c6739a35.js

GitHub Action to set up an Aerospike database. Secure drop-in replacement for reugn/github-action-aerospike.

10/10
reactive-firewall/python-bandit-scan

reactive-firewall/python-bandit-scan

GitHub Action for Python Bandit SAST

4/10
yonasbsd/iggy/.github/actions/utils/setup-node-with-cache

yonasbsd/iggy/.github/actions/utils/setup-node-with-cache

Iggy is the persistent message streaming platform written in Rust, supporting QUIC, TCP and HTTP transport protocols, capable of processing millions of messages per second.

3/10
Maintained action available