StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

open-telemetry/assign-reviewers-action

open-telemetry/assign-reviewers-action

GitHub action to assign reviewers/approvers/etc based on configuration

5/10
MathieuSoysal/hiden-dependency-updater

MathieuSoysal/hiden-dependency-updater

Update automatically dependency that Dependabot can't check.

4/10
MobSF/mobsfscan

MobSF/mobsfscan

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

4/10
step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/auto-assign-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

An action which adds reviewers to the pull request when the pull request is opened. Secure drop-in replacement for kentaro-m/auto-assign-action.

10/10
greenled/no-merge-commits-check

greenled/no-merge-commits-check

Action for checking no merge commits are present in a pull request

3/10
actions/download-artifact

actions/download-artifact

8/10
rapidsai/shared-actions/dockerhub-script

rapidsai/shared-actions/dockerhub-script

6/10
ministryofjustice/hmpps-assess-risks-and-needs-github-actions/.github/actions/cypress/merge_timings

ministryofjustice/hmpps-assess-risks-and-needs-github-actions/.github/actions/cypress/merge_timings

Reusable Github workflows and actions across the ARNS space (bootstrapped 2025-02-24)

4/10
mikaelvesavuori/standardlint-action

mikaelvesavuori/standardlint-action

This Action makes it even easier to use StandardLint in your GitHub CI runs.

3/10
manticoresoftware/paths-filter

manticoresoftware/paths-filter

Conditionally run actions based on files modified by PR, feature branch or pushed commits

2/10
step-security/actions-hugo

step-security/actions-hugo

GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported. Secure drop-in replacement for peaceiris/actions-hugo.

10/10
Maintained by StepSecurity
step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/setup-ko/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Secure drop-in replacement for ko-build/setup-ko.

10/10
pilosus/action-pip-license-checker

pilosus/action-pip-license-checker

GitHub Action for license compliance: Python, JavaScript, iOS, Android and more.

5/10
flexion/check-contributor-allowlist-action

flexion/check-contributor-allowlist-action

2/10
OZI-Project/publish

OZI-Project/publish

OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release

6/10
corentinmusard/otel-cicd-action

corentinmusard/otel-cicd-action

Open Telemetry CI/CD Action

2/10
bsord/helm-push

bsord/helm-push

Push local chart to hosted chart museum repository

3/10
elastic/oblt-actions/slack/send

elastic/oblt-actions/slack/send

7/10
depot/build-push-action

depot/build-push-action

GitHub Action to build and push Docker images with Depot

4/10
OSS-Docs-Tools/code-owner-self-merge

OSS-Docs-Tools/code-owner-self-merge

A GitHub Action for letting CODEOWNERS merge PRs via green PR reviews

3/10