Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 1k 92

  2. dev-machine-guard Public

    Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages — in seconds.

    Shell 48 8

  3. secure-repo Public

    Orchestrate GitHub Actions Security

    Go 314 50

  4. github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 499 306

Repositories

Showing 10 of 279 repositories
  • github-actions-pr-is-linked-to-work-item Public

    Check for linked Azure DevOps work item. Secure drop-in replacement for danhellem/github-actions-pr-is-linked-to-work-item.

    TypeScript 0 MIT 1 0 10 Updated Mar 27, 2026
  • setup-tflint Public

    A GitHub action that installs Terraform linter TFLint. Secure drop-in replacement for terraform-linters/setup-tflint.

    JavaScript 0 MIT 1 0 10 Updated Mar 27, 2026
  • find-comment Public

    A GitHub action to find an issue or pull request comment. Secure drop-in replacement for peter-evans/find-comment.

    TypeScript 0 MIT 1 0 11 Updated Mar 27, 2026
  • auto-approve-action Public

    👍 GitHub Action for automatically approving GitHub pull requests. Secure drop-in replacement for hmarr/auto-approve-action.

    TypeScript 0 MIT 1 0 9 Updated Mar 27, 2026
  • action-create-branch Public

    Github action to create a branch. Secure drop-in replacement for peterjgrainger/action-create-branch.

    TypeScript 0 MIT 1 0 9 Updated Mar 27, 2026
  • create-issue-from-file Public

    A GitHub action to create an issue using content from a file. Secure drop-in replacement for peter-evans/create-issue-from-file.

    TypeScript 0 MIT 1 0 9 Updated Mar 27, 2026
  • synthetics-ci-github-action Public

    Run Synthetic tests in your GitHub workflows with Datadog Continuous Testing. Secure drop-in replacement for DataDog/synthetics-ci-github-action.

    TypeScript 0 Apache-2.0 1 1 15 Updated Mar 27, 2026
  • setup-terraform Public

    Sets up Terraform CLI in your GitHub Actions workflow. Secure drop-in replacement for hashicorp/setup-terraform.

    0 0 0 1 Updated Mar 27, 2026
  • gh-find-current-pr Public

    Github Action for finding the Pull Request (PR) associated with the current SHA. Secure drop-in replacement for jwalton/gh-find-current-pr.

    TypeScript 0 MIT 1 1 10 Updated Mar 27, 2026
  • action-gh-release Public

    GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.

    TypeScript 0 MIT 1 1 3 Updated Mar 27, 2026