StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

papeloto/action-zip

papeloto/action-zip

๐Ÿ—„๏ธ Action for zipping files easily

3/10
nvidia/aicr/.github/actions/gpu-validate-conformance

nvidia/aicr/.github/actions/gpu-validate-conformance

Tooling for optimized, validated, and reproducible GPU-accelerated AI runtime in Kubernetes

7/10
tomasreyes/kafka/.github/actions/gh-api-update-status

tomasreyes/kafka/.github/actions/gh-api-update-status

Mirror of Apache Kafka

3/10
Maintained action available
vendic/github-add-changelog-action

vendic/github-add-changelog-action

Extract changelog entries and add to CHANGELOG.md

0/10
step-security/commitlint-github-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/commitlint-github-action/__builder_checkout_dir__/.github/actions/privacy-check

Lints Pull Request commits with commitlint. Secure drop-in replacement for wagoid/commitlint-github-action.

8/10
rapidsai/shared-actions/telemetry-dispatch-stash-base-env-vars

rapidsai/shared-actions/telemetry-dispatch-stash-base-env-vars

6/10
launchdarkly/php-server-sdk-redis-phpredis/.github/actions/publish-docs

launchdarkly/php-server-sdk-redis-phpredis/.github/actions/publish-docs

Redis integration for the LaunchDarkly SDK for Server-side PHP using phpredis

5/10
listendev/action

listendev/action

Proactive security monitoring and threat detection in CI/CD

4/10
mdjahid11978-design/next.js-1/.github/actions/upload-turboyet-data

mdjahid11978-design/next.js-1/.github/actions/upload-turboyet-data

The React Framework

3/10
crazy-max/ghaction-setup-docker

crazy-max/ghaction-setup-docker

GitHub Action to set up (download and install) Docker CE

6/10
databricks/cli

databricks/cli

Databricks CLI

4/10
Maintained action available
snyk/actions/gradle-jdk12

snyk/actions/gradle-jdk12

A set of GitHub actions for checking your projects for vulnerabilities.

4/10
lisanna-dettwyler/action-post-run

lisanna-dettwyler/action-post-run

Enables executing custom commands once a workflow job has ended.

2/10
yonasbsd/juicefs/.github/actions/build

yonasbsd/juicefs/.github/actions/build

JuiceFS is a distributed POSIX file system built on top of Redis and S3.

3/10
Maintained action available
dekinderfiets/pr-name-enforcer

dekinderfiets/pr-name-enforcer

2/10
timschoenle/portfolio/.github/actions/restore-build

timschoenle/portfolio/.github/actions/restore-build

Personal portfolio built with Next.js

5/10
Maintained action available
elastic/elastic-otel-java/.github/workflows/validate-tag

elastic/elastic-otel-java/.github/workflows/validate-tag

8/10
step-security/metadata-action/__builder_checkout_dir__/.github/actions/privacy-check

step-security/metadata-action/__builder_checkout_dir__/.github/actions/privacy-check

GitHub Action to extract metadata (tags, labels) from Git reference and GitHub events for Docker. Secure drop-in replacement for docker/metadata-action.

10/10
aszc/change-string-case-action

aszc/change-string-case-action

Github Action: Make a string lowercase, uppercase, or capitalized

6/10
mitre/saf_action

mitre/saf_action

GitHub Action for SAF CLI

4/10
Maintained action available