Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 861 74

  2. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 294 49

  3. wait-for-secrets wait-for-secrets Public

    Publish from GitHub Actions using multi-factor authentication

    TypeScript 288 20

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 478 286

Repositories

Showing 10 of 124 repositories
  • setup-yq Public

    Sets up YQ, yet-another-markup-language-query-er, for use in your Github Actions workflow. Secure drop-in replacement for chrisdickinson/setup-yq.

    step-security/setup-yq’s past year of commit activity
    JavaScript 0 Apache-2.0 4 1 11 Updated Aug 8, 2025
  • setup-vals Public

    Github Action for installing vals (https://github.com/helmfile/vals). Secure drop-in replacement for jkroepke/setup-vals.

    step-security/setup-vals’s past year of commit activity
    TypeScript 0 MIT 1 1 13 Updated Aug 8, 2025
  • filter-sarif Public

    GitHub Action for filtering Code Scanning alerts by path and id. Secure drop-in replacement for advanced-security/filter-sarif.

    step-security/filter-sarif’s past year of commit activity
    Java 0 Apache-2.0 1 1 2 Updated Aug 8, 2025
  • action-send-mail Public

    A GitHub Action to send an email to multiple recipients. Secure drop-in replacement for dawidd6/action-send-mail.

    step-security/action-send-mail’s past year of commit activity
    JavaScript 0 MIT 1 1 13 Updated Aug 8, 2025
  • short-sha Public

    Github Action to shorten the git SHA1 and make it accessible in outputs. Secure drop-in replacement for benjlevesque/short-sha.

    step-security/short-sha’s past year of commit activity
    TypeScript 0 MIT 1 1 11 Updated Aug 8, 2025
  • actions-hugo Public

    GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported. Secure drop-in replacement for peaceiris/actions-hugo.

    step-security/actions-hugo’s past year of commit activity
    TypeScript 0 MIT 1 1 7 Updated Aug 8, 2025
  • s3-actions-cache Public

    Cache to S3 storage with official actions/cache@v2 fallback. Secure drop-in replacement for tespkg/actions-cache.

    step-security/s3-actions-cache’s past year of commit activity
    TypeScript 1 MIT 2 1 12 Updated Aug 8, 2025
  • mise-action Public

    jdx/mise-action is a GitHub Action that integrates the mise tool into your CI/CD workflows. Secure drop-in replacement for jdx/mise-action.

    step-security/mise-action’s past year of commit activity
    TypeScript 0 MIT 1 1 9 Updated Aug 8, 2025
  • setup-applanga-cli Public

    Secure drop-in replacement for applanga/setup-applanga-cli.

    step-security/setup-applanga-cli’s past year of commit activity
    JavaScript 0 MIT 1 1 6 Updated Aug 8, 2025
  • create-json Public

    Github Action to create a .json file to use in other steps of the workflow. Secure drop-in replacement for jsdaniell/create-json.

    step-security/create-json’s past year of commit activity
    JavaScript 0 MIT 3 1 7 Updated Aug 8, 2025

Most used topics

Loading…