StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

reality2byte/action/autobuild

reality2byte/action/autobuild

5/10
Maintained action available
passeidireto/deregister-aws-amis-action

passeidireto/deregister-aws-amis-action

GitHub Action that deregisters AMIs older than a custom age that matches a given name filter

2/10
honeycombio/gha-buildevents

honeycombio/gha-buildevents

Trace GitHub Action workflows with Honeycomb

7/10
slsa-framework/slsa-github-generator

slsa-framework/slsa-github-generator

Language-agnostic SLSA provenance generation for Github Actions

6/10
ministryofjustice/hmpps-github-shared-actions/.github/actions/tool-installers/setup-kubectl

ministryofjustice/hmpps-github-shared-actions/.github/actions/tool-installers/setup-kubectl

Shared actions for Github workflows to use - PUT NO WORKFLOWS IN HERE! (bootstrapped 2026-03-30)

4/10
test-summary/action

test-summary/action

Show a helpful summary of test results in GitHub Actions CI/CD workflow runs

3/10
andrew-chen-wang/github-wiki-action

andrew-chen-wang/github-wiki-action

๐Ÿ“– GitHub Action to sync a folder to the GitHub wiki

5/10
ministryofjustice/hmpps-github-actions-runner-security/.github/actions/cloud-platform-auth

ministryofjustice/hmpps-github-actions-runner-security/.github/actions/cloud-platform-auth

A special version of the Github Actions Runner specifically to run OWASP security scans (bootstrapped 2025-08-18)

6/10
yonasbsd/greptimedb/.github/actions/publish-github-release

yonasbsd/greptimedb/.github/actions/publish-github-release

An open-source, cloud-native, distributed time-series database with PromQL/SQL/Python supported.

5/10
Maintained action available
vmactions/omnios-vm

vmactions/omnios-vm

Use omnios in github actions

3/10
Maintained action available
mikepenz/gradle-dependency-submission

mikepenz/gradle-dependency-submission

Calculates dependencies for a Gradle build-target and submits the list to the Dependency Submission API

3/10
jonathancombs782/next.js/.github/actions/next-stats-action

jonathancombs782/next.js/.github/actions/next-stats-action

The React Framework

2/10
ariga/atlas-action/schema/plan/approve

ariga/atlas-action/schema/plan/approve

GitHub Actions for Atlas

4/10
Maintained action available
koj-co/delete-merged-action

koj-co/delete-merged-action

๐Ÿ—‘๏ธ๐ŸŽฌ GitHub Action to delete merged branches (highly configurable)

3/10
sqlc-dev/setup-sqlc

sqlc-dev/setup-sqlc

GitHub Action to install sqlc

5/10
Maintained action available
launchdarkly/sdk-meta/.github/actions/ci

launchdarkly/sdk-meta/.github/actions/ci

SDK Metadata.

4/10
Maintained action available
paddlehq/go-pgdump/.github/actions/setup-databases

paddlehq/go-pgdump/.github/actions/setup-databases

Go library to create PostgreSQL dumps without external dependencies.

4/10
yonasbsd/dokku/.github/actions/build-image

yonasbsd/dokku/.github/actions/build-image

A docker-powered PaaS that helps you build and manage the lifecycle of applications

3/10
Maintained action available
surrealdb/rocksdb/.github/actions/windows-build-steps

surrealdb/rocksdb/.github/actions/windows-build-steps

A library that provides an embeddable, persistent key-value store for fast storage.

5/10
Maintained action available
nodoubtz-record-label/terraform/.github/actions/equivalence-test

nodoubtz-record-label/terraform/.github/actions/equivalence-test

Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.

3/10