StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

ossf/scorecard-monitor

ossf/scorecard-monitor

Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts

8/10
nvidia/nemo/.github/actions/cancel-workflow

nvidia/nemo/.github/actions/cancel-workflow

A scalable generative AI framework built for researchers and developers working on Large Language Models, Multimodal, and Speech AI (Automatic Speech Recognition and Text-to-Speech)

4/10
Maintained action available
grafana/mimir/operations/mimir-rules-action

grafana/mimir/operations/mimir-rules-action

Grafana Mimir provides horizontally scalable, highly available, multi-tenant, long-term storage for Prometheus.

7/10
caffeelake/cilium/../cilium-base-branch/set-runtime-image

caffeelake/cilium/../cilium-base-branch/set-runtime-image

eBPF-based Networking, Security, and Observability

3/10
kong/public-shared-actions/security-actions/semgrep

kong/public-shared-actions/security-actions/semgrep

Shared actions available to both public and private repositories

6/10
r-lib/actions/setup-r.action

r-lib/actions/setup-r.action

GitHub Actions for the R community

8/10
datadog/junit-upload-github-action

datadog/junit-upload-github-action

GitHub Action to Upload JunitXML files to Test Optimization

5/10
nexus-actions/create-nexus-staging-repo

nexus-actions/create-nexus-staging-repo

Avoid split staging repos when publishing to Maven Central

2/10
dblock/create-a-github-issue

dblock/create-a-github-issue

A GitHub Action for creating a new issue from a template file.

6/10
octopusdeploy/create-release-action

octopusdeploy/create-release-action

| Public | :octocat: GitHub Action to Create a Release in Octopus Deploy

7/10
checkmarx/kics-github-action

checkmarx/kics-github-action

GitHub actions of KICS scan - Keeping Infrastructure as Code Secure

6/10
securedotcom/agent-os-action

securedotcom/agent-os-action

Agent OS Code Reviewer - Automated code quality analysis

5/10
Maintained action available
yonasbsd/iggy/.github/actions/java-gradle/pre-merge

yonasbsd/iggy/.github/actions/java-gradle/pre-merge

Iggy is the persistent message streaming platform written in Rust, supporting QUIC, TCP and HTTP transport protocols, capable of processing millions of messages per second.

3/10
Maintained action available
devops-actions/load-available-actions

devops-actions/load-available-actions

Load all actions stored in the current organization

7/10
protocolbuffers/protobuf-ci/checkout

protocolbuffers/protobuf-ci/checkout

A shared repository for Protobuf CI actions

4/10
spotdemo4/nur/.github/actions/init

spotdemo4/nur/.github/actions/init

extra packages, bundlers and libs for nix

6/10
hayawata3626/team-approval-checker

hayawata3626/team-approval-checker

This GitHub Action checks the approvals for a pull request based on specified team conditions.

4/10
Maintained action available
software-mansion/setup-universal-sierra-compiler

software-mansion/setup-universal-sierra-compiler

Sets up universal-sierra-compiler in your Github Actions workflow

2/10
swahtz/include-guards-check-action

swahtz/include-guards-check-action

A GitHub Action to check for include guards in C/C++ header files

3/10
step-security/launchdarkly-gha-flags/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/launchdarkly-gha-flags/__builder_checkout_dir__/.github/actions/secure-download-artifact

Evaluate LaunchDarkly flags in your GitHub Action workflow. Secure drop-in replacement for launchdarkly/gha-flags.

10/10