StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

EnricoMi/publish-unit-test-result-action/linux

EnricoMi/publish-unit-test-result-action/linux

GitHub Action to publish unit test results on GitHub

3/10
Maintained action available
kentaro-m/task-completed-checker-action

kentaro-m/task-completed-checker-action

:ballot_box_with_check: A GitHub action that checks if all tasks are completed in the pull requests.

2/10
Maintained action available
meta-introspector/checkout

meta-introspector/checkout

Action for checking out a repo

2/10
NVIDIA/blossom-action

NVIDIA/blossom-action

Github action used for internal ci-cd pipeline

2/10
slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout

slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout

Language-agnostic SLSA provenance generation for Github Actions

4/10
step-security/changeset-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/changeset-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Secure drop-in replacement for changesets/action.

10/10
pytorch/pytorch/.github/actions/reuse-old-whl

pytorch/pytorch/.github/actions/reuse-old-whl

Tensors and Dynamic neural networks in Python with strong GPU acceleration

5/10
Maintained action available
softprops/action-gh-release/_next/static/chunks/11621-dab816603cd195b7.js

softprops/action-gh-release/_next/static/chunks/11621-dab816603cd195b7.js

📦 :octocat: GitHub Action for creating GitHub Releases

5/10
Maintained action available
pytorch/pytorch/.github/actions/pytest-cache-upload

pytorch/pytorch/.github/actions/pytest-cache-upload

Tensors and Dynamic neural networks in Python with strong GPU acceleration

5/10
Maintained action available
yonasBSD/dragonfly/.github/actions/sync-valkey-tests

yonasBSD/dragonfly/.github/actions/sync-valkey-tests

A modern replacement for Redis and Memcached

2/10
Maintained action available
buildless/setup-node

buildless/setup-node

Set up your GitHub Actions workflow with a specific version of node.js

2/10
zoispag/action-assign-milestone

zoispag/action-assign-milestone

GitHub action to assign a milestone to pull requests

2/10
hastd/blue-build-github-action

hastd/blue-build-github-action

Reusable GitHub Action to build custom images

5/10
Maintained action available
sandersaarond/shared-workflows/actions/publish-backend-plugin-on-site

sandersaarond/shared-workflows/actions/publish-backend-plugin-on-site

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

0/10
yonasBSD/buck2/.github/actions/build_bootstrap

yonasBSD/buck2/.github/actions/build_bootstrap

Build system, successor to Buck

3/10
Maintained action available
chronograph-pe/get-current-time

chronograph-pe/get-current-time

This action sets the current ISO8601 time to the time output and also provides readableTime, formattedTime, and many more digital outputs like year, day, second, etc. Useful for setting build times in subsequent steps, renaming your artifact, or keeping the same recorded time for the entire workflow.

2/10
step-security/dependabot-fetch-metadata/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/dependabot-fetch-metadata/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

Extract information about the dependencies being updated by a Dependabot-generated PR. Secure drop-in replacement for dependabot/fetch-metadata.

10/10
taktile-org/trigger-workflow-and-wait

taktile-org/trigger-workflow-and-wait

Trigger a workflow in another (or same) repository and wait for the job to finish.

3/10
actions-security-demo/pytorch/.github/actions/upload-sccache-stats

actions-security-demo/pytorch/.github/actions/upload-sccache-stats

Tensors and Dynamic neural networks in Python with strong GPU acceleration

2/10
step-security/repo-file-sync-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

step-security/repo-file-sync-action/__BUILDER_CHECKOUT_DIR__/.github/actions/secure-download-artifact

🔄 GitHub Action to keep files like Action workflows or entire directories in sync between multiple repositories. Secure drop-in replacement for BetaHuhn/repo-file-sync-action.

10/10