StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

checkmarx/dustilock

checkmarx/dustilock

DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.

6/10
step-security/run-vcpkg/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/run-vcpkg/__builder_checkout_dir__/.github/actions/secure-download-artifact

The GitHub Action to setup vcpkg for your C++ based projects. Stores built ports using Binary Caching backed onto GH Cache. Secure drop-in replacement for lukka/run-vcpkg.

10/10
minicli/action-contributors

minicli/action-contributors

GitHub Action to dynamically update CONTRIBUTORS file

3/10
slashgear/action-check-pr-title

slashgear/action-check-pr-title

Github action to check Pull Request title based on JS Regexp This action in really simple and use Github Action core library base on event of your pull requests No need to install anything on your runner to use it. Simple, fast, reliable ๐ŸŽ‰

3/10
kong/slsa-generator/.github/actions/generate-builder

kong/slsa-generator/.github/actions/generate-builder

Language-agnostic SLSA provenance generation for Github Actions

3/10
ericcornelissen/odgen-action/all

ericcornelissen/odgen-action/all

A GitHub Action for ODGen

4/10
sasobadovinac/occt/.github/actions/cmake-build-basic

sasobadovinac/occt/.github/actions/cmake-build-basic

Open CASCADE Technology (OCCT) is an open-source software development platform for 3D CAD, CAM, CAE. This is a clone of the official repository located on https://dev.opencascade.org/. Please use official development portal for registering issues and providing patches.

5/10
Maintained action available
kubernetes-sigs/kubebuilder-release-tools

kubernetes-sigs/kubebuilder-release-tools

Release tooling for KubeBuilder projects.

4/10
dekinderfiets/pr-description-enforcer

dekinderfiets/pr-description-enforcer

2/10
step-security/github-action-aerospike/_next/static/chunks/52206-c3a78c17c6739a35.js

step-security/github-action-aerospike/_next/static/chunks/52206-c3a78c17c6739a35.js

GitHub Action to set up an Aerospike database. Secure drop-in replacement for reugn/github-action-aerospike.

10/10
reactive-firewall/python-bandit-scan

reactive-firewall/python-bandit-scan

GitHub Action for Python Bandit SAST

3/10
shivammathur/setup-php/sitemap.xml

shivammathur/setup-php/sitemap.xml

GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and various tools.

8/10
yuya-takeyama/monotonix/actions/load-jobs

yuya-takeyama/monotonix/actions/load-jobs

Make deployment monotonous

2/10
sonarsource/sonar-java-symbolic-execution/.actions/get-build-number

sonarsource/sonar-java-symbolic-execution/.actions/get-build-number

Sonar Java symbolic execution plugin

6/10
jimver/cuda-toolkit

jimver/cuda-toolkit

GitHub Action to install CUDA

6/10
yonasbsd/iggy/.github/actions/utils/setup-node-with-cache

yonasbsd/iggy/.github/actions/utils/setup-node-with-cache

Iggy is the persistent message streaming platform written in Rust, supporting QUIC, TCP and HTTP transport protocols, capable of processing millions of messages per second.

3/10
Maintained action available
n0-computer/discord-webhook-notify

n0-computer/discord-webhook-notify

Sends a notification to discord using a webhook URL. It is written in JavaScript so it will work with windows, osx, and linux execution environments.

2/10
abatilo/actions-poetry

abatilo/actions-poetry

GitHub Actions for Python projects using poetry

7/10
sabinghost19/voucher-based-build-integrity-action

sabinghost19/voucher-based-build-integrity-action

2/10
yonasbsd/surrealdb/.github/actions/quality-check

yonasbsd/surrealdb/.github/actions/quality-check

A scalable, distributed, collaborative, document-graph database, for the realtime web

5/10
Maintained action available