StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

centml/dynamo/.github/actions/compliance-scan

centml/dynamo/.github/actions/compliance-scan

A Datacenter Scale Distributed Inference Serving Framework

4/10
Maintained action available
nvidia/onnxruntime/.github/actions/macos-ci-setup

nvidia/onnxruntime/.github/actions/macos-ci-setup

ONNX Runtime: cross-platform, high performance ML inferencing and training accelerator

3/10
grafana/sigma-rule-deployment/actions/convert

grafana/sigma-rule-deployment/actions/convert

Automate the conversion and deployment of Sigma Rules to Grafana Alerting via GitHub Actions

8/10
dhth/composite-actions/.github/actions/lint-actions

dhth/composite-actions/.github/actions/lint-actions

2/10
smartcontractkit/push-gha-metrics-action

smartcontractkit/push-gha-metrics-action

3/10
mnrendra/jajal-docker2-action

mnrendra/jajal-docker2-action

4/10
aerospike/java-object-mapper/.github/actions/stage-release-artifacts

aerospike/java-object-mapper/.github/actions/stage-release-artifacts

The Java Object Mapper is a simple, light-weight framework used to map POJOs to the Aerospike database. Using simple annotations or a configuration YAML file to describe how to map the data to Aerospike, the project takes the tedium out of mapping the data through the powerful, low level interface.

7/10
coursgranja91-hash/erk/.github/actions/setup-python-uv

coursgranja91-hash/erk/.github/actions/setup-python-uv

erk is a tool for the orchestration and management of plan-oriented agentic engineering.

3/10
zlatko-ms/envarfiles

zlatko-ms/envarfiles

Loads GitHub env variables from JSON, YAML and Plain text files

4/10
mikefarah/yq

mikefarah/yq

yq is a portable command-line YAML, JSON, XML, CSV, TOML, HCL and properties processor

9/10
home-assistant/builder

home-assistant/builder

Home Assistant builder script

8/10
nsphung/mcp-snowflake-server

nsphung/mcp-snowflake-server

MCP Snowflake Server NSP - A Snowflake MCP server โ€” SQL queries, schema exploration, and data insights for AI assistants

8/10
tanker187/node/node/.github/actions/install-clang

tanker187/node/node/.github/actions/install-clang

npm's fork of nodejs/node, for sending PRs to update deps/npm

4/10
Maintained action available
yonasbsd/testcontainers-node/.github/actions/docker-rootless-setup

yonasbsd/testcontainers-node/.github/actions/docker-rootless-setup

Testcontainers is a NodeJS library that supports tests, providing lightweight, throwaway instances of common databases, Selenium web browsers, or anything else that can run in a Docker container.

4/10
Maintained action available
johnnymorganz/stylua-action

johnnymorganz/stylua-action

GitHub action for StyLua

3/10
ryankurte/action-apt

ryankurte/action-apt

Apt action for installing multiarch packages within ubuntu gihub-actions runners

3/10
step-security/alls-green/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/alls-green/__builder_checkout_dir__/.github/actions/secure-download-artifact

A check for whether the dependency jobs are all green. Secure drop-in replacement for re-actors/alls-green.

10/10
gocodealone/github-action-matrix-outputs-write

gocodealone/github-action-matrix-outputs-write

Workaround implementation - Write matrix jobs outputs

2/10
grafana/plugin-ci-workflows/actions/plugins/release-please

grafana/plugin-ci-workflows/actions/plugins/release-please

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

4/10
Maintained action available
git-hub-chris/visualstudiocode/actions/classifier-deep/monitor

git-hub-chris/visualstudiocode/actions/classifier-deep/monitor

Microsoft Visual Studio Code.

6/10