Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 964 83

  2. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 303 51

  3. wait-for-secrets wait-for-secrets Public

    Publish from GitHub Actions using multi-factor authentication

    TypeScript 294 20

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 494 303

Repositories

Showing 10 of 244 repositories
  • push-to-gcr-github-action Public

    An action that build docker image and push to Google Cloud Registry and Google Artifact Registry. Secure drop-in replacement for RafikFarhad/push-to-gcr-github-action.

    step-security/push-to-gcr-github-action’s past year of commit activity
    0 0 0 1 Updated Feb 20, 2026
  • tfclean Public

    tfclean is tool to remove applied moved block, import block, etc. Secure drop-in replacement for takaishi/tfclean.

    step-security/tfclean’s past year of commit activity
    0 0 0 1 Updated Feb 20, 2026
  • step-security/action-semantic-demo’s past year of commit activity
    TypeScript 0 Apache-2.0 0 2 40 Updated Feb 20, 2026
  • github-tag-action Public

    A Github Action to automatically bump and tag master, on merge, with the latest SemVer formatted version. Works on any platform. Secure drop-in replacement for mathieudutour/github-tag-action.

    step-security/github-tag-action’s past year of commit activity
    TypeScript 0 MIT 1 1 10 Updated Feb 20, 2026
  • install-jq-action Public

    Multiplatform jq installer action. Secure drop-in replacement for dcarbone/install-jq-action.

    step-security/install-jq-action’s past year of commit activity
    Shell 0 Apache-2.0 1 1 5 Updated Feb 20, 2026
  • tag-push-action Public

    Github action to copy/retag multiarch images from one registry to another. Secure drop-in replacement for akhilerm/tag-push-action.

    step-security/tag-push-action’s past year of commit activity
    0 0 0 1 Updated Feb 20, 2026
  • zip-release Public

    GitHub action that can be used to create release zip archive. Secure drop-in replacement for TheDoctor0/zip-release.

    step-security/zip-release’s past year of commit activity
    Shell 0 MIT 1 0 5 Updated Feb 20, 2026
  • actions-rs-toolchain Public

    🛠️ GitHub Action for `rustup` commands. Secure drop-in replacement for actions-rs/toolchain.

    step-security/actions-rs-toolchain’s past year of commit activity
    TypeScript 0 MIT 1 1 10 Updated Feb 20, 2026
  • ghcommit-action Public

    GitHub Action to commit files to a git branch using the ghcommit utility. Secure drop-in replacement for planetscale/ghcommit-action.

    step-security/ghcommit-action’s past year of commit activity
    Shell 0 Apache-2.0 1 1 8 Updated Feb 20, 2026
  • deployment-action Public

    GitHub action to create a Deployment. Secure drop-in replacement for chrnorm/deployment-action.

    step-security/deployment-action’s past year of commit activity
    TypeScript 0 MIT 1 0 10 Updated Feb 20, 2026

Top languages

Loading…

Most used topics

Loading…