actions/cache
Cache dependencies and build outputs in GitHub Actions
GitHub Actions security score
| actions/cache | |
|---|---|
Score | 7/10 |
License | MIT License |
Maintained | 3 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 4 |
Vulnerabilities | 1 existing vulnerabilities detected |
Branch protection | branch protection not enabled on development/release branches |
Manual code review | - |
Secure publishing | - |
Signed commits | - |
Automated security tools | - |
Popular | Used by 58048 open-source projects |
Security Policy | security policy file detected |
Networking Behavior of actions/cache
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
Popular DestinationUnknown Destination
| Network Destination | Owner |
|---|---|
| ipfs-4.eri1.filebase.io | Unknown |
| ipfs-swarm.greyh.at | Unknown |
| moewe.myqnapcloud.com | Unknown |
| ipfs-e7c6p.settlemint.com | Unknown |
| sv16.bootstrap.libp2p.io | Unknown |
| prtcacprodeus2file7.blob.core.windows.net | Unknown |
| ftpmirror.your.org | Unknown |
| mirror.umd.edu | Unknown |
| security.ubuntu.com | |
| repos.eggycrew.com | Unknown |
| ipfs-store-cfc9p.settlemint.com | Unknown |
| git.io | Unknown |
| pypi.org | |
| files.pythonhosted.org | |
| auth.safetycli.com | Unknown |
| api.github.com | |
| cli.codecov.io | |
| keybase.io | Unknown |
| ingest.codecov.io | |
| o26192.ingest.us.sentry.io | Unknown |
| codeclimate.com | Unknown |
| d3iz1jjs17r6kg.cloudfront.net | Unknown |
| mirror.gcr.io | Unknown |
| checkip.amazonaws.com | Unknown |
| ghcr.io | |
| pkg-containers.githubusercontent.com | |
| news.zaproxy.org | Unknown |
| raw.githubusercontent.com | |
| cfu.zaproxy.org | Unknown |
| github.com | |
| objects.githubusercontent.com | |
| firefox.settings.services.mozilla.com | Unknown |
| r10.o.lencr.org | Unknown |
| content-signature-2.cdn.mozilla.net | Unknown |
| data.streamlit.io | Unknown |
| webhooks.fivetran.com | Unknown |
| firefox-settings-attachments.cdn.mozilla.net | Unknown |
| tel.zaproxy.org | Unknown |
| r11.o.lencr.org | Unknown |
| global.endpoint.security.microsoft.com | |
| wdcp.microsoft.com | |
| go.microsoft.com | |
| definitionupdates.microsoft.com | |
| x.cp.wd.microsoft.com | |
| winatp-gw-cus.microsoft.com | |
| us-v20.events.data.microsoft.com | |
| unitedstates.cp.wd.microsoft.com | |
| storage.googleapis.com | |
| check.trivy.dev | Unknown |
| fseeazasi4rqdij6hw2harq3.blob.core.windows.net | Unknown |
| sum.golang.org | Unknown |
| release-assets.githubusercontent.com | |
| releases.hashicorp.com | |
| packages.microsoft.com | |
| azure.archive.ubuntu.com | |
| esm.ubuntu.com | |
| evbgu32ymljjq7ar3zgaq674.blob.core.windows.net | Unknown |
| repo.maven.apache.org | Unknown |
| api.sonarcloud.io | |
| sonarcloud.io | |
| scanner.sonarcloud.io | |
| analysis-sensorcache-eu-central-1-prod.s3.eu-central-1.amazonaws.com | Unknown |
| example.com | Unknown |
| capnproto.org | Unknown |
| static.rust-lang.org | Unknown |
| proxy.golang.org | |
| registry.npmjs.org | |
| api.osv.dev | Unknown |
| index.crates.io | Unknown |
| static.crates.io | Unknown |
| checkstyle.org | Unknown |