StepSecurity Logo
StepSecurity
LoginStart free

Assess the risk of third-party GitHub Actions

Actions

Assess all the actions

step-security/protobuf-ci/__builder_checkout_dir__/.github/actions/public-layout.tsx

step-security/protobuf-ci/__builder_checkout_dir__/.github/actions/public-layout.tsx

A shared repository for Protobuf CI actions. Secure drop-in replacement for protocolbuffers/protobuf-ci.

10/10
aerospike/aerospike-client-java/.github/actions/publish-build-info-to-jfrog

aerospike/aerospike-client-java/.github/actions/publish-build-info-to-jfrog

Aerospike Java Client Library

6/10
cybrking/thr8

cybrking/thr8

Automatically generate PASTA threat models from your repo using Claude AI.

3/10
Maintained action available
redpanda-data/redpanda/ghca/actions/slash-command-error

redpanda-data/redpanda/ghca/actions/slash-command-error

Redpanda is a streaming data platform for developers. Kafka API compatible. 10x faster. No ZooKeeper. No JVM!

4/10
Maintained action available
redpanda-data/llvm-project/.github/workflows/get-llvm-version

redpanda-data/llvm-project/.github/workflows/get-llvm-version

The LLVM Project is a collection of modular and reusable compiler and toolchain technologies. Note: the repository does not accept github pull requests at this moment. Please submit your patches at http://reviews.llvm.org.

3/10
hiddenlayerai/hiddenlayer-model-scan-github-action

hiddenlayerai/hiddenlayer-model-scan-github-action

Official HiddenLayer Github Action for the Model Scanner

7/10
palewire/install-python-pipenv-pipfile

palewire/install-python-pipenv-pipfile

Easily install Python, pipenv and Pipfile packages in your GitHub Action

3/10
step-security/action-install-gh-release

step-security/action-install-gh-release

GitHub Action to install the Github Release binaries. Secure drop-in replacement for jaxxstorm/action-install-gh-release.

10/10
Maintained by StepSecurity
ministryofjustice/laa-manage-your-civil-cases/.github/actions/deploy

ministryofjustice/laa-manage-your-civil-cases/.github/actions/deploy

A service to centrally manage civil legal aid cases for the Legal Aid Agency

7/10
rudderlabs/kata-containers/.github/cargo-deny-composite-action

rudderlabs/kata-containers/.github/cargo-deny-composite-action

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/

3/10
actionutils/create-release-pr

actionutils/create-release-pr

WIP

1/10
prateek-stepsecurity/harden-runner

prateek-stepsecurity/harden-runner

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

4/10
Maintained action available
mitchellh/vouch/action/check-pr

mitchellh/vouch/action/check-pr

A community trust management system based on explicit vouches to participate.

5/10
Maintained action available
karancode/yamllint-github-action

karancode/yamllint-github-action

Github Action for linting yaml files using yamllint

4/10
step-security/setup-xcode

step-security/setup-xcode

Set up your GitHub Actions workflow with a specific version of Xcode. Secure drop-in replacement for maxim-lobanov/setup-xcode.

10/10
Maintained by StepSecurity
pytorch/tensordict/test-infra/.github/actions/teardown-windows

pytorch/tensordict/test-infra/.github/actions/teardown-windows

TensorDict is a pytorch dedicated tensor container.

4/10
Maintained action available
casadi/commercial_solvers

casadi/commercial_solvers

Set up commercial solvers in CI for testing purposes

3/10
Maintained action available
asottile/workflows/.github/actions/fast-checkout

asottile/workflows/.github/actions/fast-checkout

reusable github workflows / actions

3/10
Maintained action available
sredevopsorg/kserve/.github/actions/kserve-dep-setup

sredevopsorg/kserve/.github/actions/kserve-dep-setup

Standardized Serverless ML Inference Platform on Kubernetes

2/10
kong/proxy-wasm-rust-response-transformer/.github/actions/setup

kong/proxy-wasm-rust-response-transformer/.github/actions/setup

Response Transformer WASM Filter written in Rust

3/10