StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

pguyot/arm-runner-action

pguyot/arm-runner-action

Run tests natively and build images directly from GitHub Actions using a chroot-based virtualized Raspberry Pi (raspios/raspbian) environment

4/10
gradle/gradle-enterprise-build-validation-scripts/.github/actions/gradle/experiment-1

gradle/gradle-enterprise-build-validation-scripts/.github/actions/gradle/experiment-1

Executable scripts to assist in validating that your Gradle and Maven builds are in an optimal state in terms of maximizing work avoidance when using Develocity.

7/10
chainguard-images/actions/scan-apk

chainguard-images/actions/scan-apk

GitHub actions for the chainguard-images

8/10
step-security/setup-jfrog-cli/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/setup-jfrog-cli/__builder_checkout_dir__/.github/actions/secure-download-artifact

Set up JFrog CLI in your GitHub Actions workflow. Secure drop-in replacement for jfrog/setup-jfrog-cli.

9/10
gnosis/cla-github-action

gnosis/cla-github-action

CLA Assistant GitHub Action

2/10
yonasbsd/rocksdb/.github/actions/install-gflags-on-macos

yonasbsd/rocksdb/.github/actions/install-gflags-on-macos

A library that provides an embeddable, persistent key-value store for fast storage.

5/10
Maintained action available
step-security/github-api-commit-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/github-api-commit-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

Commits changes to the repository through the Github api instead of traditional git commands. Secure drop-in replacement for grafana/github-api-commit-action.

10/10
int128/kaniko-action

int128/kaniko-action

Build container image using Kaniko in GitHub Actions

5/10
Maintained action available
zephyrproject-rtos/action-s3-cache

zephyrproject-rtos/action-s3-cache

Cache dependencies and build outputs to S3

3/10
jetli/wasm-pack-action

jetli/wasm-pack-action

Install `wasm-pack` by downloading the executable

3/10
bit-tasks/pull-request

bit-tasks/pull-request

Build pull request and update lane task for CI/CD

0/10
Maintained action available
org-deacc-sec/no-secrets-here/.github/actions/safe-action

org-deacc-sec/no-secrets-here/.github/actions/safe-action

Empty Repo

2/10
grafana/writers-toolkit/vale-action

grafana/writers-toolkit/vale-action

Technical documentation guidelines for Grafana Labs documentation

6/10
harden-runner-canary/caffeine/.github/actions/run-gradle

harden-runner-canary/caffeine/.github/actions/run-gradle

A high performance caching library for Java

4/10
github/contributors

github/contributors

GitHub Action that given an organization or repository, produces information about the contributors over the specified time period.

7/10
uncenter/setup-taplo

uncenter/setup-taplo

Setup Taplo in GitHub Actions.

3/10
pyvista/setup-headless-display-action

pyvista/setup-headless-display-action

GitHub Action to setup a headless display on Linux and Windows (not needed on MacOS)

5/10
action-pack/tag-exists

action-pack/tag-exists

Action to determine if a tag exists.

2/10
grafana/shared-workflows/_shared-workflows-check-drone-signature/actions/get-vault-secrets

grafana/shared-workflows/_shared-workflows-check-drone-signature/actions/get-vault-secrets

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

6/10
docker/setup-compose-action

docker/setup-compose-action

GitHub Action to set up Docker Compose

7/10