StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

divd-nl/cna-bot

divd-nl/cna-bot

GitHub action to validate and submit CVE entries using cvelib, cvelint and cve service.

4/10
treosh/lighthouse-ci-action

treosh/lighthouse-ci-action

Audit URLs using Lighthouse and test performance with Lighthouse CI.

4/10
Maintained action available
contosoenterprise/variable-substitution

contosoenterprise/variable-substitution

Enable GitHub developers to parameterize the values in their config files from a GitHub Action workflow

3/10
scribe-security/action-bom

scribe-security/action-bom

Github action to Collect, Create and Store SBOM evidence

2/10
smartcontractkit/.github/actions/get-pr-labels

smartcontractkit/.github/actions/get-pr-labels

reusable GHA workflows and actions

5/10
Maintained action available
step-security/openapitools-generator-action

step-security/openapitools-generator-action

Generate a client library using the OpenAPITools Generator. Secure drop-in replacement for openapi-generators/openapitools-generator-action.

10/10
Maintained by StepSecurity
jfheinrich-eu/psono-secret-whisperer

jfheinrich-eu/psono-secret-whisperer

A GitHub Action for securely retrieving secrets from PSONO server

4/10
step-security/upload-release-action

step-security/upload-release-action

Upload files to a GitHub release. Secure drop-in replacement for svenstaro/upload-release-action.

8/10
Maintained by StepSecurity
cycjimmy/semantic-release-action

cycjimmy/semantic-release-action

GitHub Action for Semantic Release

5/10
Maintained action available
openzeppelin/openzeppelin-contracts/.github/actions/setup

openzeppelin/openzeppelin-contracts/.github/actions/setup

OpenZeppelin Contracts is a library for secure smart contract development.

6/10
gittools/actions

gittools/actions

GitHub Action that installs and uses the GitVersion and GitReleaseManager tools

6/10
w3c/spec-prod

w3c/spec-prod

GitHub Action to build ReSpec/Bikeshed specs, validate output and publish to GitHub pages or W3C

5/10
Maintained action available
tyriis/docker-image-tag-exists

tyriis/docker-image-tag-exists

GitHub Action to check if a docker container image exists in a registry.

2/10
saschanowak/clovercodecoveragesummary

saschanowak/clovercodecoveragesummary

A GitHub Action that reads Clover format code coverage files from your test suite and outputs a markdown summary

4/10
Maintained action available
christian-draeger/increment-semantic-version

christian-draeger/increment-semantic-version

3/10
stoplightio/spectral-action

stoplightio/spectral-action

GitHub Action wrapper for Spectral - a JSON/YAML/OpenAPI/AsyncAPI/etc linter with custom rule support.

3/10
google/osv-scanner-action/osv-reporter-action

google/osv-scanner-action/osv-reporter-action

8/10
briansmith/codecov-codecov-action

briansmith/codecov-codecov-action

GitHub Action that uploads coverage to Codecov :open_umbrella:

3/10
appleboy/lambda-action

appleboy/lambda-action

GitHub Action for Deploying Lambda code to an existing function

3/10
surrealdb/rocksdb/.github/actions/setup-upstream

surrealdb/rocksdb/.github/actions/setup-upstream

A library that provides an embeddable, persistent key-value store for fast storage.

5/10
Maintained action available