GitHub Action Advisor

Assess the risk of third-party GitHub Actions

step-security/add-pr-comment

step-security/add-pr-comment

Secure drop-in replacement for mshick/add-pr-comment

GitHub Action which adds a comment to a pull request's issue.

10/10
Maintained by StepSecurity
step-security/mise-action

step-security/mise-action

Secure drop-in replacement for jdx/mise-action

jdx/mise-action is a GitHub Action that integrates the mise tool into your CI/CD workflows.

10/10
Maintained by StepSecurity
step-security/helm-gh-pages

step-security/helm-gh-pages

Secure drop-in replacement for stefanprodan/helm-gh-pages

A GitHub Action for publishing Helm charts to Github Pages.

10/10
Maintained by StepSecurity
step-security/setup-gcloud

step-security/setup-gcloud

Secure drop-in replacement for google-github-actions/setup-gcloud

A GitHub Action for installing and configuring the gcloud CLI.

10/10
Maintained by StepSecurity
step-security/dynamodb-actions

step-security/dynamodb-actions

Secure drop-in replacement for mooyoul/dynamodb-actions

Integrate Github Action with Amazon DynamoDB.

10/10
Maintained by StepSecurity
step-security/secrets-sync-action

step-security/secrets-sync-action

Secure drop-in replacement for jpoehnelt/secrets-sync-action

A Github Action that can sync secrets from one repository to many others.

10/10
Maintained by StepSecurity
step-security/action-semantic-pull-request

step-security/action-semantic-pull-request

Secure drop-in replacement for amannn/action-semantic-pull-request

GitHub Action that ensures that your PR title matches the Conventional Commits spec.

10/10
Maintained by StepSecurity
step-security/action-discord

step-security/action-discord

Secure drop-in replacement for Ilshidur/action-discord

🚀 GitHub Action that sends a Discord message. .

10/10
Maintained by StepSecurity
step-security/s3-actions-cache/restore

step-security/s3-actions-cache/restore

Secure drop-in replacement for tespkg/actions-cache/restore

Cache to S3 storage with official actions/cache@v2 fallback.

10/10
Maintained by StepSecurity
step-security/setup-buildx-action

step-security/setup-buildx-action

Secure drop-in replacement for docker/setup-buildx-action

GitHub Action to set up Docker Buildx.

10/10
Maintained by StepSecurity
step-security/release-notes-generator-action

step-security/release-notes-generator-action

Secure drop-in replacement for Decathlon/release-notes-generator-action

Action to auto generate a release note based on your events.

10/10
Maintained by StepSecurity
step-security/s3-actions-cache

step-security/s3-actions-cache

Secure drop-in replacement for tespkg/actions-cache

Cache to S3 storage with official actions/cache@v2 fallback.

10/10
Maintained by StepSecurity
step-security/cirruslabs-cache

step-security/cirruslabs-cache

Secure drop-in replacement for cirruslabs/cache

Cache dependencies and build outputs in GitHub Actions.

10/10
Maintained by StepSecurity
step-security/assign-author

step-security/assign-author

Secure drop-in replacement for technote-space/assign-author

GitHub Actions to assign author to issue or PR.

10/10
Maintained by StepSecurity
step-security/setup-kubectl

step-security/setup-kubectl

Secure drop-in replacement for azure/setup-kubectl

GitHub Action for installing Kubectl.

10/10
Maintained by StepSecurity
step-security/google-github-auth

step-security/google-github-auth

Secure drop-in replacement for google-github-actions/auth

A GitHub Action for authenticating to Google Cloud.

10/10
Maintained by StepSecurity
step-security/git-auto-commit-action

step-security/git-auto-commit-action

Secure drop-in replacement for stefanzweifel/git-auto-commit-action

Automatically commit and push changed files back to GitHub with this GitHub Action for the 80% use case.

10/10
Maintained by StepSecurity
step-security/rust-cache

step-security/rust-cache

Secure drop-in replacement for Swatinem/rust-cache

A GitHub Action that implements smart caching for rust/cargo projects.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/macos

step-security/publish-unit-test-result-action/macos

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/macos

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/windows

step-security/publish-unit-test-result-action/windows

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/windows

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/setup-bun

step-security/setup-bun

Secure drop-in replacement for oven-sh/setup-bun

Set up your GitHub Actions workflow with a specific version of Bun.

10/10
Maintained by StepSecurity
step-security/ghaction-setup-docker

step-security/ghaction-setup-docker

Secure drop-in replacement for crazy-max/ghaction-setup-docker

GitHub Action to set up (download and install) Docker CE.

10/10
Maintained by StepSecurity
step-security/action-markdownlint

step-security/action-markdownlint

Secure drop-in replacement for reviewdog/action-markdownlint

Run markdownlint with reviewdog.

10/10
Maintained by StepSecurity
step-security/action-misspell

step-security/action-misspell

Secure drop-in replacement for reviewdog/action-misspell

Run misspell with reviewdog.

10/10
Maintained by StepSecurity
step-security/nats-action

step-security/nats-action

Secure drop-in replacement for onichandame/nats-action

start nats server(s) for Github Actions.

10/10
Maintained by StepSecurity
step-security/s3-actions-cache/save

step-security/s3-actions-cache/save

Secure drop-in replacement for tespkg/actions-cache/save

Cache to S3 storage with official actions/cache@v2 fallback.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/docker

step-security/publish-unit-test-result-action/docker

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/docker

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/workflow-dispatch

step-security/workflow-dispatch

Secure drop-in replacement for benc-uk/workflow-dispatch

A GitHub Action for triggering workflows, using the `workflow_dispatch` event.

10/10
Maintained by StepSecurity
step-security/git-restore-mtime-action

step-security/git-restore-mtime-action

Secure drop-in replacement for chetan/git-restore-mtime-action

A GitHub Workflow Action which restores timestamps of files in the current tree.

10/10
Maintained by StepSecurity
step-security/linkinator-action

step-security/linkinator-action

Secure drop-in replacement for JustinBeckwith/linkinator-action

A GitHub Action that checks your README and other markdown for 404s.

10/10
Maintained by StepSecurity
step-security/paths-filter

step-security/paths-filter

Secure drop-in replacement for dorny/paths-filter

Conditionally run actions based on files modified by PR, feature branch or pushed commits.

10/10
Maintained by StepSecurity
step-security/envsubst-action

step-security/envsubst-action

Secure drop-in replacement for danielr1996/envsubst-action

Github Action for envsubst.

10/10
Maintained by StepSecurity
step-security/pr-labeler-action

step-security/pr-labeler-action

Secure drop-in replacement for TimonVS/pr-labeler-action

Automatically labels your PRs based on branch name patterns like feature/* or fix/*.

10/10
Maintained by StepSecurity
step-security/create-json

step-security/create-json

Secure drop-in replacement for jsdaniell/create-json

Github Action to create a .json file to use in other steps of the workflow.

10/10
Maintained by StepSecurity
step-security/semver-utils

step-security/semver-utils

Secure drop-in replacement for madhead/semver-utils

One-stop shop for working with semantic versions in your GitHub Actions workflows.

10/10
Maintained by StepSecurity
step-security/change-string-case-action

step-security/change-string-case-action

Secure drop-in replacement for ASzc/change-string-case-action

Github Action: Make a string lowercase, uppercase, or capitalized.

10/10
Maintained by StepSecurity
step-security/gh-actions-lua

step-security/gh-actions-lua

Secure drop-in replacement for leafo/gh-actions-lua

GitHub action for Lua/LuaJIT.

10/10
Maintained by StepSecurity
step-security/r-lib-actions/setup-tinytex

step-security/r-lib-actions/setup-tinytex

Secure drop-in replacement for r-lib/actions/setup-tinytex

GitHub Actions for the R community.

10/10
Maintained by StepSecurity
step-security/foundry-toolchain

step-security/foundry-toolchain

Secure drop-in replacement for foundry-rs/foundry-toolchain

GitHub action to install Foundry.

10/10
Maintained by StepSecurity
step-security/r-lib-actions/setup-r

step-security/r-lib-actions/setup-r

Secure drop-in replacement for r-lib/actions/setup-r

GitHub Actions for the R community.

10/10
Maintained by StepSecurity
step-security/run-vcpkg

step-security/run-vcpkg

Secure drop-in replacement for lukka/run-vcpkg

The GitHub Action to setup vcpkg for your C++ based projects. Stores built ports using Binary Caching backed onto GH Cache.

10/10
Maintained by StepSecurity
step-security/mozilla-sops-action

step-security/mozilla-sops-action

Secure drop-in replacement for mdgreenwald/mozilla-sops-action

GitHub Action for installing Sops.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/misc/action/package-downloads

step-security/publish-unit-test-result-action/misc/action/package-downloads

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/misc/action/package-downloads

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/misc/action/json-output

step-security/publish-unit-test-result-action/misc/action/json-output

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/misc/action/json-output

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/increment

step-security/increment

Secure drop-in replacement for action-pack/increment

Action to increment a repository variable.

10/10
Maintained by StepSecurity
step-security/actions-hugo

step-security/actions-hugo

Secure drop-in replacement for peaceiris/actions-hugo

GitHub Actions for Hugo ⚡️ Setup Hugo quickly and build your site fast. Hugo extended, Hugo Modules, Linux (Ubuntu), macOS, and Windows are supported.

10/10
Maintained by StepSecurity
step-security/test-summary-action

step-security/test-summary-action

Secure drop-in replacement for test-summary/action

Show a helpful summary of test results in GitHub Actions CI/CD workflow runs.

10/10
Maintained by StepSecurity
step-security/create-or-update-pull-request-action

step-security/create-or-update-pull-request-action

Secure drop-in replacement for gr2m/create-or-update-pull-request-action

A GitHub Action to create or update a pull request based on local changes.

10/10
Maintained by StepSecurity
step-security/setup-gh-cli-action

step-security/setup-gh-cli-action

Secure drop-in replacement for sersoft-gmbh/setup-gh-cli-action

A GitHub action that installs or updates the gh CLI.

10/10
Maintained by StepSecurity
step-security/actions-find-and-replace-string

step-security/actions-find-and-replace-string

Secure drop-in replacement for mad9000/actions-find-and-replace-string

A GitHub action to execute find-and-replace on strings.

10/10
Maintained by StepSecurity
step-security/get-cmake

step-security/get-cmake

Secure drop-in replacement for lukka/get-cmake

Install and Cache latest CMake and Ninja for your workflows on your GitHub.

10/10
Maintained by StepSecurity
step-security/conventional-pr-title-action

step-security/conventional-pr-title-action

Secure drop-in replacement for aslafy-z/conventional-pr-title-action

Ensure your PR title matches the Conventional Commits spec.

10/10
Maintained by StepSecurity
step-security/ghaction-import-gpg

step-security/ghaction-import-gpg

Secure drop-in replacement for crazy-max/ghaction-import-gpg

GitHub Action to import a GPG key.

10/10
Maintained by StepSecurity
step-security/close-milestone

step-security/close-milestone

Secure drop-in replacement for Akkjon/close-milestone

A Github action to remove a milestone by the milestone's name.

10/10
Maintained by StepSecurity
step-security/vitest-coverage-report-action

step-security/vitest-coverage-report-action

Secure drop-in replacement for davelosert/vitest-coverage-report-action

A GitHub Action to report vitest test coverage results.

10/10
Maintained by StepSecurity
step-security/npm-get-version-action

step-security/npm-get-version-action

Secure drop-in replacement for martinbeentjes/npm-get-version-action

This Action scans for a package.json file and reads the version number from that.

10/10
Maintained by StepSecurity
step-security/github-actions-slack

step-security/github-actions-slack

Secure drop-in replacement for archive/github-actions-slack

Github Action for sending message (and reactions/threads/update/blocks) to Slack - With support for Slack's optional arguments.

10/10
Maintained by StepSecurity
step-security/esigner-codesign

step-security/esigner-codesign

Secure drop-in replacement for sslcom/esigner-codesign

GitHub Action for CodeSigner by SSL.com.

10/10
Maintained by StepSecurity
step-security/short-sha

step-security/short-sha

Secure drop-in replacement for benjlevesque/short-sha

Github Action to shorten the git SHA1 and make it accessible in outputs.

10/10
Maintained by StepSecurity
step-security/ghaction-setup-containerd

step-security/ghaction-setup-containerd

Secure drop-in replacement for crazy-max/ghaction-setup-containerd

GitHub Action to set up containerd.

10/10
Maintained by StepSecurity
step-security/action-setup

step-security/action-setup

Secure drop-in replacement for pnpm/action-setup

Install pnpm package manager.

10/10
Maintained by StepSecurity
step-security/action-slack-notify

step-security/action-slack-notify

Secure drop-in replacement for rtCamp/action-slack-notify

GitHub Action for sending a notification to a Slack channel.

10/10
Maintained by StepSecurity
step-security/action-gh-release

step-security/action-gh-release

Secure drop-in replacement for softprops/action-gh-release

GitHub Action for creating GitHub Releases.

10/10
Maintained by StepSecurity
step-security/github-action-get-latest-release

step-security/github-action-get-latest-release

Secure drop-in replacement for pozetroninc/github-action-get-latest-release

A Github action to get the latest release from another repository.

10/10
Maintained by StepSecurity
step-security/slackify-markdown-action

step-security/slackify-markdown-action

Secure drop-in replacement for LoveToKnow/slackify-markdown-action

GitHub Action to convert markdown into Slack's mrkdwn.

10/10
Maintained by StepSecurity
step-security/action-cond

step-security/action-cond

Secure drop-in replacement for haya14busa/action-cond

Conditional value for GitHub Action - missing expression for GitHub Actions .

10/10
Maintained by StepSecurity
step-security/setup-just

step-security/setup-just

Secure drop-in replacement for extractions/setup-just

🤖 GitHub Action to install the just command runner.

10/10
Maintained by StepSecurity
step-security/set-github-variable

step-security/set-github-variable

Secure drop-in replacement for mmoyaferrer/set-github-variable

Use this Github Action to update a variable in your Github Action Workflows for your repository.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/windows/bash

step-security/publish-unit-test-result-action/windows/bash

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/windows/bash

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action

step-security/publish-unit-test-result-action

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/setup-yq

step-security/setup-yq

Secure drop-in replacement for chrisdickinson/setup-yq

Sets up YQ, yet-another-markup-language-query-er, for use in your Github Actions workflow.

10/10
Maintained by StepSecurity
step-security/changeset-action

step-security/changeset-action

Secure drop-in replacement for changesets/action

10/10
Maintained by StepSecurity
step-security/workflow-conclusion-action

step-security/workflow-conclusion-action

Secure drop-in replacement for technote-space/workflow-conclusion-action

GitHub action to get workflow conclusion.

10/10
Maintained by StepSecurity
step-security/r-lib-actions/setup-pandoc

step-security/r-lib-actions/setup-pandoc

Secure drop-in replacement for r-lib/actions/setup-pandoc

GitHub Actions for the R community.

10/10
Maintained by StepSecurity
step-security/background-action

step-security/background-action

Secure drop-in replacement for JarvusInnovations/background-action

Background commands with log tailing/capture; waits until file/port/socket/http are ready to proceed. Isolates/dedupe errors.

10/10
Maintained by StepSecurity
step-security/jest-coverage-report-action

step-security/jest-coverage-report-action

Secure drop-in replacement for ArtiomTr/jest-coverage-report-action

Track your code coverage in every pull request.

10/10
Maintained by StepSecurity
step-security/changed-files

step-security/changed-files

Secure drop-in replacement for tj-actions/changed-files

Github action to retrieve all (added, copied, modified, deleted, renamed, type changed, unmerged, unknown) files and directories.

10/10
Maintained by StepSecurity
step-security/setup-vals

step-security/setup-vals

Secure drop-in replacement for jkroepke/setup-vals

Github Action for installing vals (https://github.com/helmfile/vals).

10/10
Maintained by StepSecurity
step-security/mongodb-github-action

step-security/mongodb-github-action

Secure drop-in replacement for supercharge/mongodb-github-action

Use MongoDB in GitHub Actions.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/composite

step-security/publish-unit-test-result-action/composite

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/composite

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/ssh-agent

step-security/ssh-agent

Secure drop-in replacement for webfactory/ssh-agent

GitHub Action to setup `ssh-agent` with a private key.

10/10
Maintained by StepSecurity
step-security/claude-code-action

step-security/claude-code-action

Secure drop-in replacement for anthropics/claude-code-action

10/10
Maintained by StepSecurity
step-security/retry

step-security/retry

Secure drop-in replacement for nick-fields/retry

Retries a GitHub Action step on failure or timeout.

10/10
Maintained by StepSecurity
step-security/gh-docker-logs

step-security/gh-docker-logs

Secure drop-in replacement for jwalton/gh-docker-logs

GitHub Action to collect logs from all docker containers.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/linux

step-security/publish-unit-test-result-action/linux

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/linux

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/action-send-mail

step-security/action-send-mail

Secure drop-in replacement for dawidd6/action-send-mail

A GitHub Action to send an email to multiple recipients.

10/10
Maintained by StepSecurity
step-security/auto-assign-issue

step-security/auto-assign-issue

Secure drop-in replacement for pozil/auto-assign-issue

GitHub Action that auto-assigns issues or PRs to one or more users.

10/10
Maintained by StepSecurity
step-security/skip-duplicate-actions

step-security/skip-duplicate-actions

Secure drop-in replacement for fkirc/skip-duplicate-actions

Save time and cost when using GitHub Actions.

10/10
Maintained by StepSecurity
step-security/runs-on-cache

step-security/runs-on-cache

Secure drop-in replacement for runs-on/cache

Shockingly faster GitHub Action cache with S3 backend.

10/10
Maintained by StepSecurity
step-security/r-lib-actions/pr-fetch

step-security/r-lib-actions/pr-fetch

Secure drop-in replacement for r-lib/actions/pr-fetch

GitHub Actions for the R community.

10/10
Maintained by StepSecurity
step-security/test-reporter

step-security/test-reporter

Secure drop-in replacement for dorny/test-reporter

Displays test results from popular testing frameworks directly in GitHub.

10/10
Maintained by StepSecurity
step-security/depot-setup-action

step-security/depot-setup-action

Secure drop-in replacement for depot/setup-action

▶️ GitHub Action to download and install the Depot CLI.

10/10
Maintained by StepSecurity
step-security/setup-zig

step-security/setup-zig

Secure drop-in replacement for mlugg/setup-zig

Install a Zig compiler for usage in GitHub Actions workflows.

10/10
Maintained by StepSecurity
step-security/actions-codespell

step-security/actions-codespell

Secure drop-in replacement for codespell-project/actions-codespell

A GitHub Actions to run codespell over your code.

10/10
Maintained by StepSecurity
step-security/ssh-key-action

step-security/ssh-key-action

Secure drop-in replacement for shimataro/ssh-key-action

GitHub Action that installs SSH key to .ssh.

10/10
Maintained by StepSecurity
step-security/multi-labeler

step-security/multi-labeler

Secure drop-in replacement for fuxingloh/multi-labeler

Multi labeler for title, body, comments, commit messages, branch, author or files with automated status checks.

10/10
Maintained by StepSecurity
step-security/publish-unit-test-result-action/misc/action/fetch-workflows

step-security/publish-unit-test-result-action/misc/action/fetch-workflows

Secure drop-in replacement for EnricoMi/publish-unit-test-result-action/misc/action/fetch-workflows

GitHub Action to publish unit test results on GitHub.

10/10
Maintained by StepSecurity
step-security/r-lib-actions/pr-push

step-security/r-lib-actions/pr-push

Secure drop-in replacement for r-lib/actions/pr-push

GitHub Actions for the R community.

10/10
Maintained by StepSecurity
step-security/claude-code-action/base-action

step-security/claude-code-action/base-action

Secure drop-in replacement for anthropics/claude-code-base-action

10/10
Maintained by StepSecurity