StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

rudderlabs/rudder-sdk-kotlin/.github/actions/test-check

rudderlabs/rudder-sdk-kotlin/.github/actions/test-check

Kotlin Android SDK and Kotlin JVM for RudderStack - the Customer Data Platform for Developers.

4/10
Maintained action available
w9jds/setup-firebase

w9jds/setup-firebase

Firebase GitHub Action (replacement for firebase-action)

2/10
yonasBSD/rspack/.github/actions/docker/linux-build

yonasBSD/rspack/.github/actions/docker/linux-build

A fast Rust-based web bundler.

5/10
Maintained action available
honeycombio/gha-buildevents

honeycombio/gha-buildevents

Trace GitHub Action workflows with Honeycomb

5/10
slsa-framework/slsa-github-generator

slsa-framework/slsa-github-generator

Language-agnostic SLSA provenance generation for Github Actions

5/10
test-summary/action

test-summary/action

Show a helpful summary of test results in GitHub Actions CI/CD workflow runs

3/10
ministryofjustice/hmpps-github-actions-runner-security/.github/actions/cloud-platform-auth

ministryofjustice/hmpps-github-actions-runner-security/.github/actions/cloud-platform-auth

A special version of the Github Actions Runner specifically to run OWASP security scans (bootstrapped 2025-08-18)

6/10
vmactions/omnios-vm

vmactions/omnios-vm

Use omnios in github actions

4/10
Maintained action available
mikepenz/gradle-dependency-submission

mikepenz/gradle-dependency-submission

Calculates dependencies for a Gradle build-target and submits the list to the Dependency Submission API

3/10
koj-co/delete-merged-action

koj-co/delete-merged-action

🗑️🎬 GitHub Action to delete merged branches (highly configurable)

3/10
sqlc-dev/setup-sqlc

sqlc-dev/setup-sqlc

GitHub Action to install sqlc

2/10
yonasBSD/paradedb/.github/actions/benchmarks-from-main

yonasBSD/paradedb/.github/actions/benchmarks-from-main

ParadeDB is a modern Elasticsearch alternative built on Postgres. Built for real-time, update-heavy workloads.

4/10
Maintained action available
sailpoint-oss/api-linter/packages/github-spectral-comment

sailpoint-oss/api-linter/packages/github-spectral-comment

Spectral Sailpoint Rulesets and Functions

3/10
Maintained action available
yonasBSD/turso/.github/shared/install_sqlite

yonasBSD/turso/.github/shared/install_sqlite

Turso Database is a project to build the next evolution of SQLite.

3/10
Maintained action available
sandersaarond/shared-workflows/actions/bundle-plugin

sandersaarond/shared-workflows/actions/bundle-plugin

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

0/10
broadsage/containers/.github/actions/build-metadata

broadsage/containers/.github/actions/build-metadata

Primary source of truth for the Broadsage Container Images

5/10
tj-actions/bandit

tj-actions/bandit

:octocat: Github action to run PyCQA's bandit security linter.

4/10
NVIDIA/aicr/.github/actions/go-lint

NVIDIA/aicr/.github/actions/go-lint

Tooling for deploying optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes

6/10
yonasBSD/opendal/.github/actions/test_behavior_binding_cpp

yonasBSD/opendal/.github/actions/test_behavior_binding_cpp

Apache OpenDAL: access data freely.

3/10
Maintained action available
n80fr1n60/secure-checkout

n80fr1n60/secure-checkout

Drop-in replacement for actions/checkout@vX.Y.Z with persist-credentials=false enforced

4/10