Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 999 89

  2. dev-machine-guard dev-machine-guard Public

    Scan your dev machine for AI agents, MCP servers, IDE extensions, and suspicious packages — in seconds.

    Shell 41 6

  3. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 309 50

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 496 303

Repositories

Showing 10 of 269 repositories
  • github-action Public

    GitHub Action for running Cypress end-to-end & component tests. Secure drop-in replacement for cypress-io/github-action.

    step-security/github-action’s past year of commit activity
    0 0 0 1 Updated Mar 16, 2026
  • unity-builder Public

    Build Unity projects for different platforms. Secure drop-in replacement for game-ci/unity-builder.

    step-security/unity-builder’s past year of commit activity
    TypeScript 0 MIT 1 0 10 Updated Mar 16, 2026
  • github-actions-pr-is-linked-to-work-item Public

    Check for linked Azure DevOps work item. Secure drop-in replacement for danhellem/github-actions-pr-is-linked-to-work-item.

    step-security/github-actions-pr-is-linked-to-work-item’s past year of commit activity
    0 0 0 1 Updated Mar 16, 2026
  • swiftylab-ci Public

    Support files and configurations for SwiftyLab's CI. Secure drop-in replacement for SwiftyLab/ci.

    step-security/swiftylab-ci’s past year of commit activity
    JavaScript 0 MIT 1 0 9 Updated Mar 16, 2026
  • action-surefire-report Public

    Reports surefire test results as GitHub Pull Request Check. Secure drop-in replacement for ScaCap/action-surefire-report.

    step-security/action-surefire-report’s past year of commit activity
    JavaScript 0 Apache-2.0 1 0 16 Updated Mar 16, 2026
  • lock-threads Public

    GitHub Action that locks closed issues, pull requests and discussions after a period of inactivity. Secure drop-in replacement for dessant/lock-threads.

    step-security/lock-threads’s past year of commit activity
    JavaScript 0 MIT 1 1 9 Updated Mar 16, 2026
  • conventional-changelog-action Public

    Github Action that generates a changelog with the Conventional Changelog CLI. Secure drop-in replacement for TriPSs/conventional-changelog-action.

    step-security/conventional-changelog-action’s past year of commit activity
    JavaScript 0 MIT 1 1 10 Updated Mar 16, 2026
  • agent Public

    Purpose-built security agent for hosted runners

    step-security/agent’s past year of commit activity
    Go 42 Apache-2.0 27 22 24 Updated Mar 16, 2026
  • secure-repo Public

    Orchestrate GitHub Actions Security

    step-security/secure-repo’s past year of commit activity
    Go 309 AGPL-3.0 50 71 491 Updated Mar 16, 2026
  • setup-swift Public

    GitHub Action to setup Swift environment. Secure drop-in replacement for SwiftyLab/setup-swift.

    step-security/setup-swift’s past year of commit activity
    TypeScript 0 MIT 1 1 12 Updated Mar 16, 2026

Most used topics

Loading…