Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 950 83

  2. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 304 51

  3. wait-for-secrets wait-for-secrets Public

    Publish from GitHub Actions using multi-factor authentication

    TypeScript 295 20

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 492 304

Repositories

Showing 10 of 220 repositories
  • terraform-stepsecurity-examples Public

    Examples of using Terraform to manage step-security resources

    step-security/terraform-stepsecurity-examples’s past year of commit activity
    0 Apache-2.0 0 0 3 Updated Jan 28, 2026
  • allure-action Public

    Secure drop-in replacement for allure-framework/allure-action.

    step-security/allure-action’s past year of commit activity
    0 0 0 1 Updated Jan 28, 2026
  • action-download-artifact Public

    ⚙️ A GitHub Action to download an artifact associated with given workflow and commit or other criteria. Secure drop-in replacement for dawidd6/action-download-artifact.

    step-security/action-download-artifact’s past year of commit activity
    JavaScript 0 MIT 1 1 9 Updated Jan 28, 2026
  • rust-cache Public

    A GitHub Action that implements smart caching for rust/cargo projects. Secure drop-in replacement for Swatinem/rust-cache.

    step-security/rust-cache’s past year of commit activity
    TypeScript 0 LGPL-3.0 1 1 18 Updated Jan 28, 2026
  • get-cmake Public

    Install and Cache latest CMake and Ninja for your workflows on your GitHub. Secure drop-in replacement for lukka/get-cmake.

    step-security/get-cmake’s past year of commit activity
    TypeScript 0 MIT 1 1 16 Updated Jan 28, 2026
  • setup-zig Public

    Install a Zig compiler for usage in GitHub Actions workflows. Secure drop-in replacement for mlugg/setup-zig.

    step-security/setup-zig’s past year of commit activity
    JavaScript 1 MIT 1 1 13 Updated Jan 28, 2026
  • mise-action Public

    jdx/mise-action is a GitHub Action that integrates the mise tool into your CI/CD workflows. Secure drop-in replacement for jdx/mise-action.

    step-security/mise-action’s past year of commit activity
    TypeScript 0 MIT 1 1 12 Updated Jan 28, 2026
  • protobuf-ci Public

    A shared repository for Protobuf CI actions. Secure drop-in replacement for protocolbuffers/protobuf-ci.

    step-security/protobuf-ci’s past year of commit activity
    0 Apache-2.0 1 0 4 Updated Jan 28, 2026
  • change-string-case-action Public

    Github Action: Make a string lowercase, uppercase, or capitalized. Secure drop-in replacement for ASzc/change-string-case-action.

    step-security/change-string-case-action’s past year of commit activity
    JavaScript 0 ISC 4 1 11 Updated Jan 28, 2026
  • cancel-action Public

    Secure drop-in replacement for andymckay/cancel-action.

    step-security/cancel-action’s past year of commit activity
    JavaScript 0 MIT 1 1 7 Updated Jan 28, 2026

Top languages

Loading…

Most used topics

Loading…