StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

hynek/build-and-inspect-python-package

hynek/build-and-inspect-python-package

Build and Inspect Python Packages in GitHub Actions

8/10
step-security/setup-uv/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/setup-uv/__builder_checkout_dir__/.github/actions/secure-download-artifact

Set up your GitHub Actions workflow with a specific version of https://docs.astral.sh/uv/. Secure drop-in replacement for astral-sh/setup-uv.

8/10
actions-tools/yaml-outputs

actions-tools/yaml-outputs

GitHub Action to read a YAML file and flatten it recursively into outputs

2/10
palewire/internet-archive-upload

palewire/internet-archive-upload

Upload files to an archive.org collection in your GitHub Action

2/10
coveord/spinnaker/.github/actions/spinnaker-release

coveord/spinnaker/.github/actions/spinnaker-release

Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence.

3/10
iancha1992/continuous-integration/actions/cherry_picker

iancha1992/continuous-integration/actions/cherry_picker

Bazel's Continuous Integration Setup

5/10
Maintained action available
metamask/security-code-scanner

metamask/security-code-scanner

A GitHub action aggregating SAST tools to scan code for vulnerabilities

2/10
nvidia/openshell/.github/actions/setup-buildx

nvidia/openshell/.github/actions/setup-buildx

OpenShell is the safe, private runtime for autonomous AI agents.

4/10
gitleaks/gitleaks-action

gitleaks/gitleaks-action

Protect your secrets using Gitleaks-Action

2/10
zimperium/zscanmarketplace

zimperium/zscanmarketplace

4/10
tecolicom/actions-use-apt-tools

tecolicom/actions-use-apt-tools

Github action for apt packages

3/10
yonasbsd/surrealdb/.github/actions/publish-binaries

yonasbsd/surrealdb/.github/actions/publish-binaries

A scalable, distributed, collaborative, document-graph database, for the realtime web

4/10
Maintained action available
step-security/changed-files

step-security/changed-files

Github action to retrieve all (added, copied, modified, deleted, renamed, type changed, unmerged, unknown) files and directories. Secure drop-in replacement for tj-actions/changed-files.

9/10
Maintained by StepSecurity
joshuathemiller/conditional-build-matrix

joshuathemiller/conditional-build-matrix

A GitHub Action that enables easier conditional matrix builds!

3/10
slsa-framework/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact

slsa-framework/slsa-github-generator/__builder_checkout_dir__/.github/actions/secure-upload-artifact

Language-agnostic SLSA provenance generation for Github Actions

5/10
politicalsphere/ci/.github/actions/consumer-contract

politicalsphere/ci/.github/actions/consumer-contract

CI/CD pipelines and GitHub Actions for Political Sphere

2/10
grafana/mimir-loki/lib/actions/push-images

grafana/mimir-loki/lib/actions/push-images

Like Prometheus, but for logs.

2/10
nvidia/aicr/.github/actions/aicr-build

nvidia/aicr/.github/actions/aicr-build

Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes

7/10
warchant/setup-sonar-scanner

warchant/setup-sonar-scanner

Github Action which downloads and runs sonar-scanner cli with custom parameters to start Sonarqube scan.

4/10
dudinea/argo-cd/__builder_checkout_dir__/.github/actions/privacy-check

dudinea/argo-cd/__builder_checkout_dir__/.github/actions/privacy-check

Declarative Continuous Deployment for Kubernetes

5/10
Maintained action available