StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/plugin-ci-workflows/actions/internal/plugins/setup

grafana/plugin-ci-workflows/actions/internal/plugins/setup

Re-usable GitHub Actions workflows for building, testing, releasing and deploying plugins

6/10
grafana/security-github-actions/trivy

grafana/security-github-actions/trivy

Repo for Security related GitHub Actions CI automation

6/10
step-security/conventional-pr-title-action/__builder_checkout_dir__/.github/actions/compute-sha256

step-security/conventional-pr-title-action/__builder_checkout_dir__/.github/actions/compute-sha256

Ensure your PR title matches the Conventional Commits spec. Secure drop-in replacement for aslafy-z/conventional-pr-title-action.

10/10
oxidecomputer/actions-rs_toolchain

oxidecomputer/actions-rs_toolchain

๐Ÿ› ๏ธ GitHub Action for `rustup` commands

2/10
step-security/action-semantic-demo

step-security/action-semantic-demo

7/10
devantler-tech/ksail/.github/actions/ksail-cluster

devantler-tech/ksail/.github/actions/ksail-cluster

All-in-one Kubernetes SDK: create, manage, and operate clusters across distributions (Kind, K3d, Talos, VCluster) with built-in GitOps, secrets, AI assistant, and MCP server. Only requires Docker or a Cloud Provider.

3/10
Maintained action available
grafana/x-ray-datasource/actions/commands

grafana/x-ray-datasource/actions/commands

AWS X-Ray data source

7/10
nv-gha-runners/setup-artifactory-go-proxy

nv-gha-runners/setup-artifactory-go-proxy

4/10
navikt/automerge-dependabot

navikt/automerge-dependabot

This action automatically merges pull requests created by Dependabot with a set of configurable rules.

8/10
pytorch/torchrec/test-infra/.github/actions/setup-ssh

pytorch/torchrec/test-infra/.github/actions/setup-ssh

Pytorch domain library for recommendation systems

3/10
Maintained action available
pytorch/executorch/test-infra/.github/actions/upload-artifact-s3

pytorch/executorch/test-infra/.github/actions/upload-artifact-s3

On-device AI across mobile, embedded and edge for PyTorch

2/10
Maintained action available
red-gate/flyway-actions/migrations/deploy

red-gate/flyway-actions/migrations/deploy

Official Redgate Actions: Set up, check, and deploy changes with Redgate Flyway

7/10
grafana/mimir-loki/lib/actions/should-release

grafana/mimir-loki/lib/actions/should-release

Like Prometheus, but for logs.

3/10
yonasbsd/wazuh/.github/actions/vulnerability_scanner/compile

yonasbsd/wazuh/.github/actions/vulnerability_scanner/compile

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

4/10
Maintained action available
nvidia/cuda-quantum/.github/actions/run-in-docker

nvidia/cuda-quantum/.github/actions/run-in-docker

C++ and Python support for the CUDA Quantum programming model for heterogeneous quantum-classical workflows

8/10
jplachance/tgf

jplachance/tgf

A Terragrunt frontend that allow execution of Terragrunt/Terraform through Docker

2/10
openzeppelin/openzeppelin-confidential-contracts/.github/actions/setup

openzeppelin/openzeppelin-confidential-contracts/.github/actions/setup

Solidity library of encrypted contracts using Zama's FHEVM

6/10
envoyproxy/toolshed/actions/dispatch

envoyproxy/toolshed/actions/dispatch

6/10
jofthev/pytorch/.github/actions/download-build-artifacts

jofthev/pytorch/.github/actions/download-build-artifacts

Tensors and Dynamic neural networks in Python with strong GPU acceleration

2/10
ledgerhq/ledger-live/tools/actions/upload-images

ledgerhq/ledger-live/tools/actions/upload-images

Mono-repository for packages related to Ledger Live and its JavaScript ecosystem.

4/10
Maintained action available