StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

grafana/grafana/.github/actions/website-sync

grafana/grafana/.github/actions/website-sync

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

4/10
Maintained action available
step-security/setup-applanga-cli

step-security/setup-applanga-cli

Secure drop-in replacement for applanga/setup-applanga-cli.

10/10
Maintained by StepSecurity
slsa-framework/slsa-github-generator/.github/actions/secure-download-folder

slsa-framework/slsa-github-generator/.github/actions/secure-download-folder

Language-agnostic SLSA provenance generation for Github Actions

5/10
repo-sync/pull-request

repo-sync/pull-request

โคต๏ธ A GitHub Action for creating pull requests

6/10
sslcom/actions-codesigner

sslcom/actions-codesigner

GitHub Action for CodeSigner by SSL.com

2/10
jakoch/install-vulkan-sdk-action

jakoch/install-vulkan-sdk-action

A Github Action to install the current Vulkan SDK and runtime library. It also supports installing SwiftShader and Lavapipe software rasterizers.

4/10
Maintained action available
securego/gosec

securego/gosec

Go security checker

8/10
fantasticfiasco/action-update-license-year

fantasticfiasco/action-update-license-year

GitHub Action that in a pull request updates the copyright year(s) in your license file.

4/10
Maintained action available
haskell/actions/setup

haskell/actions/setup

Github actions for Haskell CI

2/10
canonical/action-publish

canonical/action-publish

A Github action for publishing snaps

2/10
grafana/mimir-loki/lib/actions/install-binary

grafana/mimir-loki/lib/actions/install-binary

Like Prometheus, but for logs.

2/10
step-security/ghaction-github-status/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/ghaction-github-status/__builder_checkout_dir__/.github/actions/secure-download-artifact

GitHub Action to check GitHub Status in your workflow. Secure drop-in replacement for crazy-max/ghaction-github-status.

8/10
koj-co/dependabot-pr-action

koj-co/dependabot-pr-action

๐Ÿ“ฆ Label, approve, and merge Dependabot pull requests automatically

3/10
nvidia/spark-rapids-common/signoff-check

nvidia/spark-rapids-common/signoff-check

Reusable GitHub Actions workflows and common scripts for Spark RAPIDS

5/10
allure-framework/setup-allurectl

allure-framework/setup-allurectl

Set up your GitHub Actions workflow with a specific version of allurectl

4/10
comfy-org/comfy-action

comfy-org/comfy-action

Sets up ComfyUI on MacOS/Linux/Windows and runs a workflow json.

2/10
huang-julien/reproduire-sur-stackblitz

huang-julien/reproduire-sur-stackblitz

Github Action send a stackblitz link to a github repo for reproductions

0/10
bufbuild/buf-setup-action

bufbuild/buf-setup-action

3/10
scalacenter/sbt-dependency-submission

scalacenter/sbt-dependency-submission

A Github Action to submit the dependency graph of an sbt build to the Dependency Submission API

6/10
reviewdog/action-tfsec

reviewdog/action-tfsec

Run tfsec with reviewdog on pull requests to enforce security best practices

6/10