StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

modeseven-lfreleng-actions/pypi-publish-action

modeseven-lfreleng-actions/pypi-publish-action

Publishes a Python project to the Python Package Index (PyPI)

4/10
Maintained action available
hashicorp/tfc-workflows-github

hashicorp/tfc-workflows-github

HCP Terraform starter workflows and github actions to automate Terraform Cloud CI/CD pipelines.

7/10
step-security/gitleaks-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

step-security/gitleaks-action/__builder_checkout_dir__/.github/actions/secure-download-artifact

Protect your secrets using Gitleaks-Action. Secure drop-in replacement for gitleaks/gitleaks-action.

8/10
martincostello/update-dotnet-sdk

martincostello/update-dotnet-sdk

A GitHub Action that updates the .NET SDK

7/10
egor-tensin/vs-shell

egor-tensin/vs-shell

GitHub action to set up the Visual Studio shell environment

5/10
coveo/ui-kit/.github/actions/e2e-stencil

coveo/ui-kit/.github/actions/e2e-stencil

Coveo UI kit repository, home of @coveo/headless, @coveo/atomic, and more.

4/10
Maintained action available
yonasbsd/rspack/.github/actions/docker/linux-build

yonasbsd/rspack/.github/actions/docker/linux-build

A fast Rust-based web bundler.

5/10
Maintained action available
slsa-framework/slsa-github-generator/.github/actions/verify-token

slsa-framework/slsa-github-generator/.github/actions/verify-token

Language-agnostic SLSA provenance generation for Github Actions

5/10
nvidia/numbast/.github/actions/docs-build

nvidia/numbast/.github/actions/docs-build

Numbast is a tool to build an automated pipeline that converts CUDA APIs into Numba bindings.

7/10
wandalen/wretry.action/post

wandalen/wretry.action/post

Retry action for Github CI

3/10
rapidsai/node/.github/actions/build-and-publish-image

rapidsai/node/.github/actions/build-and-publish-image

GPU-accelerated data science and visualization in node

3/10
snapshift/action-check-typescript

snapshift/action-check-typescript

2/10
huntridge-labs/argus/.github/actions/linter-dockerfile

huntridge-labs/argus/.github/actions/linter-dockerfile

Argus brings โ€œa hundred eyesโ€ to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline.

3/10
grafana/synthetic-monitoring-agent/.github/actions/go-cache-save

grafana/synthetic-monitoring-agent/.github/actions/go-cache-save

Synthetic Monitoring agent

8/10
eseay/setup-git-credentials

eseay/setup-git-credentials

GitHub action to clone private respositories.

3/10
dtolnay/install

dtolnay/install

Fast `cargo install` action using a GitHub-based binary cache and attestations

3/10
rematocorp/open-pull-request-action

rematocorp/open-pull-request-action

GitHub action for automatically creating a pull request

3/10
winterjung/split

winterjung/split

GitHub action to split string

3/10
step-security/yaml-update-action

step-security/yaml-update-action

Update YAML property with dynamic values. Secure drop-in replacement for fjogeleit/yaml-update-action.

8/10
Maintained by StepSecurity
be-hase/gradle-dependency-diff-action

be-hase/gradle-dependency-diff-action

2/10