StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

tue-robotics/tue-env/ci/modified-packages

tue-robotics/tue-env/ci/modified-packages

Package manager that can be used to install (ROS) dependencies

6/10
PostHog/posthog-github-action

PostHog/posthog-github-action

Capture CI/CD metrics in PostHog - workflow duration, success rates, and performance trends

6/10
pytorch/pytorch.github.io/test-infra/.github/actions/setup-windows

pytorch/pytorch.github.io/test-infra/.github/actions/setup-windows

The website for PyTorch

3/10
Maintained action available
getong/elasticsearch-action

getong/elasticsearch-action

3/10
MetaMask/Security-Code-Scanner

MetaMask/Security-Code-Scanner

A GitHub action aggregating SAST tools to scan code for vulnerabilities

2/10
buildkite/trigger-pipeline-action

buildkite/trigger-pipeline-action

A GitHub Action for triggering a build on a Buildkite pipeline.

6/10
peter-murray/workflow-application-token-action

peter-murray/workflow-application-token-action

GitHub Action that will get a scoped short lived token for Actions workflows using a GitHub Application.

4/10
antoncoding/gas-diff-action

antoncoding/gas-diff-action

Compares gas usage in Solidity projects using Foundry and comments the changes on the PR

2/10
jungwinter/split

jungwinter/split

GitHub action to split string

4/10
sfackler/actions/rustfmt

sfackler/actions/rustfmt

2/10
snyk/actions/php

snyk/actions/php

A set of GitHub actions for checking your projects for vulnerabilities.

4/10
wuz/publish-to-npm

wuz/publish-to-npm

A Github Action to publish to NPM

2/10
pytorch/executorch/test-infra/.github/actions/run-script-with-cache

pytorch/executorch/test-infra/.github/actions/run-script-with-cache

On-device AI across mobile, embedded and edge for PyTorch

2/10
Maintained action available
JakePartusch/wait-for-netlify-action

JakePartusch/wait-for-netlify-action

A GitHub action that will wait until a Netlify Preview deploy has completed before continuing on

2/10
upptime/updates

upptime/updates

⬆️🆕 Deployment of important updates for @upptime

3/10
ministryofjustice/hmpps-github-actions/.github/actions/auditjson_to_sarif

ministryofjustice/hmpps-github-actions/.github/actions/auditjson_to_sarif

Github actions for HMPPS projects

6/10
mnrendra/asu/.github/actions/release

mnrendra/asu/.github/actions/release

5/10
ministryofjustice/opg-reports/.github/actions/docker-build-scan-push

ministryofjustice/opg-reports/.github/actions/docker-build-scan-push

Development repository: Managed by opg-org-infra & Terraform

8/10
step-security/dummy-compromised-action

step-security/dummy-compromised-action

A harmless GitHub Action designed to test enforcement of the Compromised Actions workflow run policy.

7/10
yonasBSD/wazuh/.github/actions/check_files

yonasBSD/wazuh/.github/actions/check_files

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

4/10
Maintained action available