StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

sormuras/download-jdk

sormuras/download-jdk

FUP2 https://github.com/oracle-actions/setup-java

3/10
tokorom/action-slack-incoming-webhook

tokorom/action-slack-incoming-webhook

GitHub Action for Slack Incoming Webhook

2/10
yonasBSD/sccache/.github/actions/nvcc-toolchain

yonasBSD/sccache/.github/actions/nvcc-toolchain

Sccache is a ccache-like tool. It is used as a compiler wrapper and avoids compilation when possible. Sccache has the capability to utilize caching in remote storage environments, including various cloud storage options, or alternatively, in local storage.

4/10
Maintained action available
microsoft/onnxruntime-github-actions/build-docker-image

microsoft/onnxruntime-github-actions/build-docker-image

Reusable GitHub Actions for ONNX Runtime repos. The actions are used for constructing ONNX Runtime's public pull request pipelines.

4/10
yonasBSD/grafana/.github/actions/build-package

yonasBSD/grafana/.github/actions/build-package

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

2/10
Maintained action available
runs-on/cache/restore

runs-on/cache/restore

Shockingly faster GitHub Action cache with S3 backend

3/10
yonasBSD/neon/.github/actions/save-coverage-data

yonasBSD/neon/.github/actions/save-coverage-data

Neon: Serverless Postgres. We separated storage and compute to offer autoscaling, branching, and bottomless storage.

2/10
yonasBSD/vector/.github/actions/pull-test-runner

yonasBSD/vector/.github/actions/pull-test-runner

A high-performance observability data pipeline.

4/10
Maintained action available
OpenZeppelin/ui-builder/.github/actions/oidc

OpenZeppelin/ui-builder/.github/actions/oidc

UI Builder is an open-source blockchain development tool that helps developers and non-developers create user-friendly interfaces for smart contract interaction by providing a chain-agnostic form builder that generates standalone "mini apps" without requiring backend infrastructure.

5/10
Maintained action available
harekrishnarai/flowlyt

harekrishnarai/flowlyt

Flowlyt is a security analyzer that scans GitHub Actions workflows to detect malicious patterns, misconfigurations, and secrets exposure, helping enforce secure CI/CD practices.

7/10
42Crunch/api-security-audit-action-freemium

42Crunch/api-security-audit-action-freemium

Freemium version of Github Action for Audit

2/10
celo-org/social-connect/.github/actions/sync-workspace

celo-org/social-connect/.github/actions/sync-workspace

Protocol mapping social identifiers to blockchain addresses

5/10
Maintained action available
ansible-community/ansible-test-gh-action

ansible-community/ansible-test-gh-action

A composite GitHub Action encapsulating the GitHub Actions CI/CD workflows setup necessary for testing Ansible collection repositories on GitHub

4/10
Maintained action available
AKJUS/bicep-registry-modules/.github/actions/templates/avm-setEnvironment

AKJUS/bicep-registry-modules/.github/actions/templates/avm-setEnvironment

Bicep registry modules

5/10
Maintained action available
step-security/jest-coverage-action-demo/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/jest-coverage-action-demo/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

8/10
step-security/pr-labeler-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

step-security/pr-labeler-action/__BUILDER_CHECKOUT_DIR__/.github/actions/privacy-check

Automatically labels your PRs based on branch name patterns like feature/* or fix/*. Secure drop-in replacement for TimonVS/pr-labeler-action.

10/10
agenthunt/conventional-commit-checker-action

agenthunt/conventional-commit-checker-action

2/10
PoliticalSphere/ci/.github/actions/license-check

PoliticalSphere/ci/.github/actions/license-check

CI/CD pipelines and GitHub Actions for Political Sphere

2/10
grafana/grafana-aws-sdk/actions/commands

grafana/grafana-aws-sdk/actions/commands

Common AWS configs for plugins

8/10
sonatype/actions/fetch-sbom

sonatype/actions/fetch-sbom

Public repository to keep Sonatype's GitHub Actions.

3/10
Maintained action available