actions/cache

actions/cache

Cache dependencies and build outputs in GitHub Actions

GitHubGitHub Repository

5145 stars

Node.js

Node Action

Score updated 6 hours ago

GitHub Actions security score

actions/cache

Score

7/10

License

MIT License

Maintained

3 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 4

Vulnerabilities

1 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 58048 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/cache

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
ipfs-4.eri1.filebase.ioUnknown
ipfs-swarm.greyh.atUnknown
moewe.myqnapcloud.comUnknown
ipfs-e7c6p.settlemint.comUnknown
sv16.bootstrap.libp2p.ioUnknown
prtcacprodeus2file7.blob.core.windows.netUnknown
ftpmirror.your.orgUnknown
mirror.umd.eduUnknown
security.ubuntu.comUbuntuUbuntu
repos.eggycrew.comUnknown
ipfs-store-cfc9p.settlemint.comUnknown
git.ioUnknown
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
auth.safetycli.comUnknown
api.github.comGitHubGitHub
cli.codecov.ioCodecovCodecov
keybase.ioUnknown
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
codeclimate.comUnknown
d3iz1jjs17r6kg.cloudfront.netUnknown
mirror.gcr.ioUnknown
checkip.amazonaws.comUnknown
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
news.zaproxy.orgUnknown
raw.githubusercontent.comGitHubGitHub
cfu.zaproxy.orgUnknown
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
firefox.settings.services.mozilla.comUnknown
r10.o.lencr.orgUnknown
content-signature-2.cdn.mozilla.netUnknown
data.streamlit.ioUnknown
webhooks.fivetran.comUnknown
firefox-settings-attachments.cdn.mozilla.netUnknown
tel.zaproxy.orgUnknown
r11.o.lencr.orgUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
x.cp.wd.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
us-v20.events.data.microsoft.comMicrosoftMicrosoft
unitedstates.cp.wd.microsoft.comMicrosoftMicrosoft
storage.googleapis.comGoogleGoogle
check.trivy.devUnknown
fseeazasi4rqdij6hw2harq3.blob.core.windows.netUnknown
sum.golang.orgUnknown
release-assets.githubusercontent.comGitHubGitHub
releases.hashicorp.comHashiCorpHashiCorp
packages.microsoft.comMicrosoftMicrosoft
azure.archive.ubuntu.comUbuntuUbuntu
esm.ubuntu.comUbuntuUbuntu
evbgu32ymljjq7ar3zgaq674.blob.core.windows.netUnknown
repo.maven.apache.orgUnknown
api.sonarcloud.ioSonarSonar
sonarcloud.ioSonarSonar
scanner.sonarcloud.ioSonarSonar
analysis-sensorcache-eu-central-1-prod.s3.eu-central-1.amazonaws.comUnknown
example.comUnknown
capnproto.orgUnknown
static.rust-lang.orgUnknown
proxy.golang.orgGolang ProxyGolang Proxy
registry.npmjs.orgnpm Registrynpm Registry
api.osv.devUnknown
index.crates.ioUnknown
static.crates.ioUnknown
checkstyle.orgUnknown