StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

projectdiscovery/actions/setup/go

projectdiscovery/actions/setup/go

ProjectDiscovery's Composite Actions

7/10
jbergstroem/hadolint-gh-action

jbergstroem/hadolint-gh-action

A Dockerfile linter using Hadolint for Github actions that provides code annotations, Github advanced security and more

3/10
vapor/swift-codecov-action

vapor/swift-codecov-action

A GitHub Action which performs Codecov.io uploads with additional support for Swift projects

7/10
oracle-actions/login-ocir

oracle-actions/login-ocir

Login to Oracle Cloud Infrastructure Registry (OCIR)

2/10
yonasbsd/surrealdb/.github/actions/build-macos

yonasbsd/surrealdb/.github/actions/build-macos

A scalable, distributed, collaborative, document-graph database, for the realtime web

5/10
Maintained action available
yonasbsd/cargo-binstall

yonasbsd/cargo-binstall

Binary installation for rust projects

5/10
Maintained action available
ministryofjustice/laa-data-claims-api/.github/actions/image

ministryofjustice/laa-data-claims-api/.github/actions/image

LAA Data Claims API

8/10
briansmith/actions-checkout

briansmith/actions-checkout

Action for checking out a repo

2/10
step-security/gh-docker-logs/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/gh-docker-logs/__builder_checkout_dir__/.github/actions/secure-download-artifact

GitHub Action to collect logs from all docker containers. Secure drop-in replacement for jwalton/gh-docker-logs.

10/10
optum/booster/.github/actions/image

optum/booster/.github/actions/image

Booster Cloud Framework

4/10
Maintained action available
yokawasa/action-setup-kube-tools

yokawasa/action-setup-kube-tools

Github Action that setup Kubernetes tools (kubectl, kustomize, helm, kubeconform, conftest, yq, rancher, tilt, skaffold) very fast and cache them on the runner. Please [✩Star] if you're using it!

5/10
Maintained action available
nvidia/nemo-retriever/.github/actions/setup-docker-buildx

nvidia/nemo-retriever/.github/actions/setup-docker-buildx

NeMo Retriever Library is a scalable, performance-oriented document content and metadata extraction microservice. NeMo Retriever Library uses specialized NVIDIA NIM microservices to find, contextualize, and extract text, tables, charts and images that you can use in downstream generative applications.

7/10
neuralegion/wait-for

neuralegion/wait-for

Action polls a NeuraLegion scan until it returns a detected issue, or its time runs out

2/10
shanegenschaw/pull-request-comment-trigger

shanegenschaw/pull-request-comment-trigger

A github action for detecting a "trigger" in a pull request description or comment

1/10
magrhino/wud-updater/.github/actions/setup-python-env

magrhino/wud-updater/.github/actions/setup-python-env

Updating docker images using WUD's Notification System

6/10
grafana/clickhouse-datasource/actions/commands

grafana/clickhouse-datasource/actions/commands

Grafana Plugin for ClickHouse

7/10
sceptre/github-ci-action

sceptre/github-ci-action

2/10
step-security/action-surefire-report/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/action-surefire-report/__builder_checkout_dir__/.github/actions/secure-download-artifact

Reports surefire test results as GitHub Pull Request Check. Secure drop-in replacement for ScaCap/action-surefire-report.

8/10
bitwarden/ios/.github/actions/public-layout.tsx

bitwarden/ios/.github/actions/public-layout.tsx

Bitwarden mobile apps (Password Manager and Authenticator) for iOS.

7/10
stakekit/signers/.github/composite_actions/initial_setup

stakekit/signers/.github/composite_actions/initial_setup

The StakeKit Signers allows you to create a signing wallet instance from a mnemonic phrase or ledger app and sign transactions

1/10