StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

re-actors/checkout-python-sdist

re-actors/checkout-python-sdist

A GitHub Action to unpack a source distribution package (tarball / `.tar.gz`) into the current workspace

3/10
elastic/oblt-actions/oblt-cli/setup

elastic/oblt-actions/oblt-cli/setup

7/10
seanmiddleditch/gha-setup-ninja

seanmiddleditch/gha-setup-ninja

GitHub Action to install the ninja build tool to PATH

5/10
politicalsphere/ci/.github/actions/ps-task/trivy

politicalsphere/ci/.github/actions/ps-task/trivy

CI/CD pipelines and GitHub Actions for Political Sphere

2/10
slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

slsa-framework/slsa-github-generator/.github/actions/secure-builder-checkout

Language-agnostic SLSA provenance generation for Github Actions

5/10
siemens/ix-starter/.github/workflows/actions/install

siemens/ix-starter/.github/workflows/actions/install

Siemens Industrial Experience is a design system for designers and developers, to consistently create the perfect digital experience for industrial software products.

3/10
pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

pytorch/pytorch-integration-testing/test-infra/.github/actions/pull-docker-image

Testing downstream libraries using pytorch release candidates

5/10
Maintained action available
step-security/ghaction-setup-docker/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/ghaction-setup-docker/__builder_checkout_dir__/.github/actions/secure-download-artifact

GitHub Action to set up (download and install) Docker CE. Secure drop-in replacement for docker/setup-docker-action.

9/10
k-paxian/dart-package-publisher

k-paxian/dart-package-publisher

Action to Publish Dart / Flutter Package To https://pub.dev When you need to publish a package, just bump the version in pubspec.yaml

4/10
andife/openvino/openvino/.github/actions/cache

andife/openvino/openvino/.github/actions/cache

OpenVINOβ„’ is an open source toolkit for optimizing and deploying AI inference

3/10
launchdarkly/ldcli/.github/actions/publish

launchdarkly/ldcli/.github/actions/publish

The official command line interface for managing LaunchDarkly feature flags.

4/10
Maintained action available
timschoenle/actions/actions/helm/update-chart-version

timschoenle/actions/actions/helm/update-chart-version

Centralized collection of reusable GitHub Actions, Workflows, and configurations.

7/10
metamask/github-tools/.github/actions/update-release-changelog

metamask/github-tools/.github/actions/update-release-changelog

An assortment of tools interacting with the GitHub API to get metrics for things like PR review comments/reviews

5/10
Maintained action available
clickhouse/checkout

clickhouse/checkout

Wrapper around actions/checkout for flexible tuning

4/10
jianlins/llama.cpp/.github/actions/windows-setup-cuda

jianlins/llama.cpp/.github/actions/windows-setup-cuda

LLM inference in C/C++

5/10
Maintained action available
grafana/plugin-ci-workflows/actions/plugins/docs/publish

grafana/plugin-ci-workflows/actions/plugins/docs/publish

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

4/10
Maintained action available
grafana/shared-workflows/actions/trigger-argo-workflow

grafana/shared-workflows/actions/trigger-argo-workflow

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

6/10
grafana/community-contributions/.github/actions/external-pr-validation/post-validation-comment

grafana/community-contributions/.github/actions/external-pr-validation/post-validation-comment

External contributor PR workflow testing sandbox

2/10
step-security/sccache-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/sccache-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

sccache github action. Secure drop-in replacement for Mozilla-Actions/sccache-action.

10/10
erpc/erpc

erpc/erpc

eRPC β€” fault-tolerant evm rpc proxy

4/10
Maintained action available