Skip to content

StepSecurity App

GitHub App

StepSecurity App

GitHub App

This App enables advanced scenarios for the StepSecurity Platform, e.g.

  1. Analysis of private GitHub Actions
  2. Creation of GitHub issues for Action misconfigurations, e.g. over-privileged GitHub token permissions
  3. Integration with GitHub Advanced Security

It needs the following permissions:

  1. Administration Read: To check branch protection of private Actions
  2. Contents Read: To evaluate score for private Actions and recommend fixes for Action misconfigurations
  3. Pull Requests Read: To evaluate score for private Actions
  4. Issues Write: To create issues to recommend fixes for Action misconfigurations
  5. Code Scanning Alerts Write: To create GitHub Advanced Security findings to recommend fixes for Action misconfigurations

This App should only be installed after the https://github.com/apps/stepsecurity-actions-security App

Developer

StepSecurity App is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.

Report abuse