StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

paddlehq/go-pgdump/.github/actions/setup-databases

paddlehq/go-pgdump/.github/actions/setup-databases

Go library to create PostgreSQL dumps without external dependencies.

4/10
yonasbsd/dokku/.github/actions/build-image

yonasbsd/dokku/.github/actions/build-image

A docker-powered PaaS that helps you build and manage the lifecycle of applications

3/10
Maintained action available
step-security/setup-compose-action

step-security/setup-compose-action

GitHub Action to set up Docker Compose. Secure drop-in replacement for docker/setup-compose-action.

10/10
Maintained by StepSecurity
surrealdb/rocksdb/.github/actions/windows-build-steps

surrealdb/rocksdb/.github/actions/windows-build-steps

A library that provides an embeddable, persistent key-value store for fast storage.

6/10
sonarsource/sonar-scala/.github/actions/orchestrator-cache

sonarsource/sonar-scala/.github/actions/orchestrator-cache

Scala analyzer

6/10
nodoubtz-record-label/terraform/.github/actions/equivalence-test

nodoubtz-record-label/terraform/.github/actions/equivalence-test

Terraform enables you to safely and predictably create, change, and improve infrastructure. It is a source-available tool that codifies APIs into declarative configuration files that can be shared amongst team members, treated as code, edited, reviewed, and versioned.

2/10
stacklet/cube/actions/author-detector

stacklet/cube/actions/author-detector

๐Ÿ“Š Cube โ€” Universal semantic layer platform for AI, BI, spreadsheets, and embedded analytics

3/10
sailpoint-oss/api-linter/packages/github-spectral-comment

sailpoint-oss/api-linter/packages/github-spectral-comment

Spectral Sailpoint Rulesets and Functions

3/10
Maintained action available
politicalsphere/ci/.github/actions/ps-pr-comment

politicalsphere/ci/.github/actions/ps-pr-comment

CI/CD pipelines and GitHub Actions for Political Sphere

2/10
sandersaarond/shared-workflows/actions/bundle-plugin

sandersaarond/shared-workflows/actions/bundle-plugin

A public-facing, centralized place to store reusable workflows used by Grafana Labs.

0/10
yonasbsd/grafana/ephemeral

yonasbsd/grafana/ephemeral

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

2/10
Maintained action available
sonarsource/sonarqube/.actions/get-build-number

sonarsource/sonarqube/.actions/get-build-number

Continuous Inspection

4/10
Maintained action available
kong/toolchain

kong/toolchain

๐Ÿ› ๏ธ GitHub Action for `rustup` commands

3/10
reality2byte/docs/.github/actions/clone-translations

reality2byte/docs/.github/actions/clone-translations

The open-source repo for docs.github.com

2/10
dotnet/docs-tools/cleanrepo/cleanrepo

dotnet/docs-tools/cleanrepo/cleanrepo

This repo contains GitHub Actions and other tools that are designed to be invoked on DocFx repositories.

4/10
Maintained action available
nvidia-nemo/export-deploy/fw-ci-templates/.github/actions/publish-docs

nvidia-nemo/export-deploy/fw-ci-templates/.github/actions/publish-docs

A library for exporting models including NeMo and Hugging Face to optimized inference backends, and deploying them for efficient querying

8/10
broadsage/containers/.github/actions/build-metadata

broadsage/containers/.github/actions/build-metadata

Primary source of truth for the Broadsage Container Images

5/10
schwma/parse-changelog-action

schwma/parse-changelog-action

GitHub action that parses a specific release from a CHANGELOG

3/10
tj-actions/bandit

tj-actions/bandit

:octocat: Github action to run PyCQA's bandit security linter.

4/10
ytanikin/prconventionalcommits

ytanikin/prconventionalcommits

2/10