StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/allure-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/allure-action/__builder_checkout_dir__/.github/actions/privacy-check

Secure drop-in replacement for allure-framework/allure-action.

10/10
microsoft/msbuild

microsoft/msbuild

The Microsoft Build Engine (MSBuild) is the build platform for .NET and Visual Studio.

7/10
tlmsllc/copilot-sdk/.github/actions/setup-copilot

tlmsllc/copilot-sdk/.github/actions/setup-copilot

Multi-platform SDK for integrating GitHub Copilot Agent into apps and services

4/10
envoyproxy/toolshed/gh-actions/bson

envoyproxy/toolshed/gh-actions/bson

7/10
dangoslen/changelog-enforcer

dangoslen/changelog-enforcer

A simple GitHub action that enforces that a maintained changelog is kept up to date.

4/10
Maintained action available
kentaro-m/task-completed-checker-action

kentaro-m/task-completed-checker-action

:ballot_box_with_check: A GitHub action that checks if all tasks are completed in the pull requests.

2/10
meta-introspector/checkout

meta-introspector/checkout

Action for checking out a repo

2/10
step-security/changeset-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/changeset-action/__builder_checkout_dir__/.github/actions/privacy-check

Secure drop-in replacement for changesets/action.

10/10
ai-dynamo/modelexpress/.github/actions/run-mx-p2p-test

ai-dynamo/modelexpress/.github/actions/run-mx-p2p-test

Model Express is a Rust-based component meant to be placed next to existing model inference systems to speed up their startup times and improve overall performance.

6/10
slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout

slsa-framework/slsa-github-generator/.github/actions/secure-project-checkout

Language-agnostic SLSA provenance generation for Github Actions

5/10
pytorch/pytorch/.github/actions/reuse-old-whl

pytorch/pytorch/.github/actions/reuse-old-whl

Tensors and Dynamic neural networks in Python with strong GPU acceleration

5/10
Maintained action available
softprops/action-gh-release/_next/static/chunks/11621-dab816603cd195b7.js

softprops/action-gh-release/_next/static/chunks/11621-dab816603cd195b7.js

๐Ÿ“ฆ :octocat: GitHub Action for creating GitHub Releases

5/10
Maintained action available
pytorch/pytorch/.github/actions/pytest-cache-upload

pytorch/pytorch/.github/actions/pytest-cache-upload

Tensors and Dynamic neural networks in Python with strong GPU acceleration

4/10
Maintained action available
buildless/setup-node

buildless/setup-node

Set up your GitHub Actions workflow with a specific version of node.js

2/10
zoispag/action-assign-milestone

zoispag/action-assign-milestone

GitHub action to assign a milestone to pull requests

2/10
hastd/blue-build-github-action

hastd/blue-build-github-action

Reusable GitHub Action to build custom images

4/10
jofthev/docs/.github/actions/setup-elasticsearch.md

jofthev/docs/.github/actions/setup-elasticsearch.md

The open-source repo for docs.github.com

0/10
sandersaarond/shared-workflows/actions/publish-backend-plugin-on-site

sandersaarond/shared-workflows/actions/publish-backend-plugin-on-site

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

0/10
step-security/short-sha/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/short-sha/__builder_checkout_dir__/.github/actions/secure-download-artifact

Github Action to shorten the git SHA1 and make it accessible in outputs. Secure drop-in replacement for benjlevesque/short-sha.

10/10
chronograph-pe/get-current-time

chronograph-pe/get-current-time

This action sets the current ISO8601 time to the time output and also provides readableTime, formattedTime, and many more digital outputs like year, day, second, etc. Useful for setting build times in subsequent steps, renaming your artifact, or keeping the same recorded time for the entire workflow.

2/10