Skip to content
@step-security

StepSecurity

Secure your GitHub Actions with StepSecurity: Your Trusted CI/CD Security Partner

Step Security Logo

Close the CI/CD Security Gap

Pinned Loading

  1. harden-runner harden-runner Public

    Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re…

    TypeScript 956 83

  2. secure-repo secure-repo Public

    Orchestrate GitHub Actions Security

    Go 303 51

  3. wait-for-secrets wait-for-secrets Public

    Publish from GitHub Actions using multi-factor authentication

    TypeScript 295 20

  4. github-actions-goat github-actions-goat Public

    GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

    JavaScript 493 304

Repositories

Showing 10 of 237 repositories
  • deployment-action Public

    GitHub action to create a Deployment. Secure drop-in replacement for chrnorm/deployment-action.

    step-security/deployment-action’s past year of commit activity
    0 0 0 0 Updated Feb 9, 2026
  • add-and-commit Public

    :octocat: Automatically commit changes made in your workflow run directly to your repo. Secure drop-in replacement for EndBug/add-and-commit.

    step-security/add-and-commit’s past year of commit activity
    0 0 0 0 Updated Feb 9, 2026
  • actions-rs-toolchain Public

    🛠️ GitHub Action for `rustup` commands. Secure drop-in replacement for actions-rs/toolchain.

    step-security/actions-rs-toolchain’s past year of commit activity
    0 0 0 1 Updated Feb 9, 2026
  • reusable-workflows Public

    StepSecurity Reusable Workflows

    step-security/reusable-workflows’s past year of commit activity
    Go 0 MIT 3 1 6 Updated Feb 9, 2026
  • action-gh-release Public

    GitHub Action for creating GitHub Releases. Secure drop-in replacement for softprops/action-gh-release.

    step-security/action-gh-release’s past year of commit activity
    TypeScript 0 MIT 1 1 3 Updated Feb 9, 2026
  • gha-setup-swift Public

    Setup Swift (on Windows) on GitHub Actions Builders. Secure drop-in replacement for compnerd/gha-setup-swift.

    step-security/gha-setup-swift’s past year of commit activity
    0 0 0 1 Updated Feb 9, 2026
  • gha-setup-vsdevenv Public

    GitHub Action to setup the VS dev environment for the job. Secure drop-in replacement for compnerd/gha-setup-vsdevenv.

    step-security/gha-setup-vsdevenv’s past year of commit activity
    0 0 0 1 Updated Feb 9, 2026
  • protobuf-ci Public

    A shared repository for Protobuf CI actions. Secure drop-in replacement for protocolbuffers/protobuf-ci.

    step-security/protobuf-ci’s past year of commit activity
    0 Apache-2.0 1 1 5 Updated Feb 9, 2026
  • release-drafter Public

    Drafts your next release notes as pull requests are merged into master. Secure drop-in replacement for release-drafter/release-drafter.

    step-security/release-drafter’s past year of commit activity
    JavaScript 0 ISC 1 0 10 Updated Feb 9, 2026
  • issue-closed-labeler-action Public

    Conditionally add or remove labels of issues when closed via a PR. Secure drop-in replacement for RebeccaStevens/issue-closed-labeler-action.

    step-security/issue-closed-labeler-action’s past year of commit activity
    TypeScript 0 BSD-3-Clause 1 0 8 Updated Feb 9, 2026