StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/action-gh-release/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/action-gh-release/__builder_checkout_dir__/.github/actions/secure-download-artifact

GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.

10/10
stainless-api/trigger-release-please

stainless-api/trigger-release-please

GitHub action that runs Release Please externally

3/10
enricomi/publish-unit-test-result-action/v2.18.0

enricomi/publish-unit-test-result-action/v2.18.0

GitHub Action to publish unit test results on GitHub

4/10
Maintained action available
ledgerhq/ledger-live/tools/actions/composites/setup-android-env

ledgerhq/ledger-live/tools/actions/composites/setup-android-env

Mono-repository for packages related to Ledger Live and its JavaScript ecosystem.

4/10
Maintained action available
grafana/synthetic-monitoring-api-go-client/_shared-workflows-publish-techdocs/actions/aws-auth

grafana/synthetic-monitoring-api-go-client/_shared-workflows-publish-techdocs/actions/aws-auth

Go client for Synthetic Monitoring

8/10
step-security/docker-login-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/docker-login-action/__builder_checkout_dir__/.github/actions/privacy-check

GitHub Action to login against a Docker registry. Secure drop-in replacement for docker/login-action.

8/10
aws-actions/codeguru-security

aws-actions/codeguru-security

5/10
pytorch/pytorch-integration-testing/test-infra/.github/actions/setup-ssh

pytorch/pytorch-integration-testing/test-infra/.github/actions/setup-ssh

Testing downstream libraries using pytorch release candidates

5/10
Maintained action available
green-coding-solutions/eco-ci-energy-estimation

green-coding-solutions/eco-ci-energy-estimation

Eco CI Energy estimation for Github Actions, GitLab and Jenkins

4/10
yonasbsd/sccache/.github/actions/artifact_failure

yonasbsd/sccache/.github/actions/artifact_failure

Sccache is a ccache-like tool. It is used as a compiler wrapper and avoids compilation when possible. Sccache has the capability to utilize caching in remote storage environments, including various cloud storage options, or alternatively, in local storage.

3/10
Maintained action available
snyk/actions/gradle-jdk16

snyk/actions/gradle-jdk16

A set of GitHub actions for checking your projects for vulnerabilities.

4/10
vexxhost/github-actions/scan-image

vexxhost/github-actions/scan-image

Common GitHub actions workflows

3/10
Maintained action available
yonasbsd/wazuh/.github/actions/image

yonasbsd/wazuh/.github/actions/image

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

4/10
Maintained action available
sonarsource/sonarlint-vscode/.github/actions/ovsx-publish

sonarsource/sonarlint-vscode/.github/actions/ovsx-publish

SonarQube extension for Visual Studio Code providing code quality and security feedback directly in the editor

6/10
sonarsource/sonar-scanner-msbuild/.actions/get-build-number

sonarsource/sonar-scanner-msbuild/.actions/get-build-number

SonarScanner for .NET

6/10
dannyhw/storybook-chromatic-link-comment

dannyhw/storybook-chromatic-link-comment

2/10
step-security/short-sha

step-security/short-sha

Github Action to shorten the git SHA1 and make it accessible in outputs. Secure drop-in replacement for benjlevesque/short-sha.

10/10
Maintained by StepSecurity
nvidia/spark-rapids-common/pr-description-check

nvidia/spark-rapids-common/pr-description-check

Reusable GitHub Actions workflows and common scripts for Spark RAPIDS

5/10
kentaro-m/auto-assign-action

kentaro-m/auto-assign-action

An action which adds reviewers to the pull request when the pull request is opened.

6/10
vendic/github-regex-extract-action

vendic/github-regex-extract-action

Extract matches from a text using regex

0/10