StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

tomhjp/gh-action-jira-create

tomhjp/gh-action-jira-create

GitHub action to create Jira tickets with customisable fields

3/10
phips28/gh-action-bump-version

phips28/gh-action-bump-version

GitHub Action for automated npm version bump.

4/10
Maintained action available
huntridge-labs/argus/.github/actions/scanner-bandit

huntridge-labs/argus/.github/actions/scanner-bandit

Argus brings β€œa hundred eyes” to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline.

2/10
deepcode-ai/codeql/ql/.github/actions/fetch-codeql

deepcode-ai/codeql/ql/.github/actions/fetch-codeql

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

2/10
jonathancombs782/bitcoin/.github/actions/save-caches

jonathancombs782/bitcoin/.github/actions/save-caches

Bitcoin Core integration/staging tree

6/10
approved-3rd-party-actions/commit-message-checker

approved-3rd-party-actions/commit-message-checker

GitHub Action that checks commit messages of pushes and pull request against a regex pattern

2/10
grafana/grafana/.github/actions/changelog

grafana/grafana/.github/actions/changelog

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

4/10
Maintained action available
hadolint/hadolint-action

hadolint/hadolint-action

GitHub action for Hadolint, A Dockerfile linting tool

6/10
surrealdb/rocksdb/.github/actions/pre-steps

surrealdb/rocksdb/.github/actions/pre-steps

A library that provides an embeddable, persistent key-value store for fast storage.

5/10
Maintained action available
aks-lts/test-infra

aks-lts/test-infra

LTS specific configuration and tooling for testing

3/10
hashicorp/sentinel-github-actions

hashicorp/sentinel-github-actions

4/10
slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact

slsa-framework/slsa-github-generator/.github/actions/secure-upload-artifact

Language-agnostic SLSA provenance generation for Github Actions

5/10
rjdbcm/ozi-publish

rjdbcm/ozi-publish

OZI action - publish releases to PyPI; and mirror releases, signature bundles, and provenance in a tagged release

7/10
masci/datadog

masci/datadog

Send Datadog metrics, events, service checks and logs from GitHub workflows

4/10
Maintained action available
kong/public-shared-actions/pr-previews/validate

kong/public-shared-actions/pr-previews/validate

Shared actions available to both public and private repositories

6/10
pytorch/text/test-infra/.github/actions/chown-directory

pytorch/text/test-infra/.github/actions/chown-directory

Models, data loaders and abstractions for language processing, powered by PyTorch

2/10
aerospike/aerospike-client-java-reactive/.github/actions/publish-build-info-to-jfrog

aerospike/aerospike-client-java-reactive/.github/actions/publish-build-info-to-jfrog

Reactive programming interfaces for the Aerospike Java client

4/10
angular/dev-infra/github-actions/bazel/configure-remote

angular/dev-infra/github-actions/bazel/configure-remote

Angular Development Infrastructure

6/10
envoyproxy/toolshed/gh-actions/jq

envoyproxy/toolshed/gh-actions/jq

6/10
pytorch/tensordict/test-infra/.github/actions/run-script-with-cache

pytorch/tensordict/test-infra/.github/actions/run-script-with-cache

TensorDict is a pytorch dedicated tensor container.

4/10
Maintained action available