Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 679 57

  2. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 274 41

  3. wait-for-secrets wait-for-secrets Public

    Publish from GitHub Actions using multi-factor authentication

    TypeScript 283 18

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 456 268

Repositories

Showing 10 of 66 repositories
  • run-vcpkg Public

    The GitHub Action to setup vcpkg for your C++ based projects. Stores built ports using Binary Caching backed onto GH Cache.

    step-security/run-vcpkg’s past year of commit activity
    TypeScript 0 MIT 1 0 11 Updated Mar 6, 2025
  • reusable-workflows Public

    StepSecurity Reusable Workflows

    step-security/reusable-workflows’s past year of commit activity
    0 MIT 1 0 6 Updated Mar 6, 2025
  • setup-gh-cli-action Public

    A GitHub action that installs or updates the gh CLI

    step-security/setup-gh-cli-action’s past year of commit activity
    TypeScript 0 MIT 1 8 11 Updated Mar 6, 2025
  • mongodb-github-action Public

    Use MongoDB in GitHub Actions

    step-security/mongodb-github-action’s past year of commit activity
    Shell 0 MIT 1 1 8 Updated Mar 6, 2025
  • vitest-coverage-report-action Public

    A GitHub Action to report vitest test coverage results

    step-security/vitest-coverage-report-action’s past year of commit activity
    TypeScript 0 MIT 1 1 8 Updated Mar 5, 2025
  • ssh-key-action Public

    GitHub Action that installs SSH key to .ssh

    step-security/ssh-key-action’s past year of commit activity
    TypeScript 0 MIT 1 1 10 Updated Mar 5, 2025
  • publish-unit-test-result-action Public

    GitHub Action to publish unit test results on GitHub

    step-security/publish-unit-test-result-action’s past year of commit activity
    Python 0 Apache-2.0 2 8 19 Updated Mar 5, 2025
  • secrets-sync-action Public

    A Github Action that can sync secrets from one repository to many others.

    step-security/secrets-sync-action’s past year of commit activity
    TypeScript 0 Apache-2.0 1 2 12 Updated Mar 4, 2025
  • workflow-conclusion-action Public

    GitHub action to get workflow conclusion.

    step-security/workflow-conclusion-action’s past year of commit activity
    TypeScript 2 MIT 1 0 10 Updated Mar 4, 2025
  • ghaction-setup-docker Public

    GitHub Action to set up (download and install) Docker CE

    step-security/ghaction-setup-docker’s past year of commit activity
    TypeScript 0 Apache-2.0 1 0 10 Updated Mar 4, 2025