StepSecurity Logo
StepSecurity
LoginStart free
actions/cache

actions/cache

Cache dependencies and build outputs in GitHub Actions

GitHubGitHub Repository

5233 stars

Node.js

Node Action

Score updated 6 days ago

GitHub Actions security score

actions/cache

Score

8/10

License

MIT License

Maintained

30 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

1 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 117888 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/cache

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
ipfs-4.eri1.filebase.ioUnknown
ipfs-swarm.greyh.atUnknown
moewe.myqnapcloud.comUnknown
ipfs-e7c6p.settlemint.comUnknown
sv16.bootstrap.libp2p.ioUnknown
prtcacprodeus2file7.blob.core.windows.netUnknown
ftpmirror.your.orgUnknown
mirror.umd.eduUnknown
security.ubuntu.comUbuntuUbuntu
repos.eggycrew.comUnknown
ipfs-store-cfc9p.settlemint.comUnknown
git.ioUnknown
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
auth.safetycli.comUnknown
api.github.comGitHubGitHub
cli.codecov.ioCodecovCodecov
keybase.ioUnknown
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
codeclimate.comUnknown
d3iz1jjs17r6kg.cloudfront.netUnknown
mirror.gcr.ioUnknown
checkip.amazonaws.comUnknown
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
news.zaproxy.orgUnknown
raw.githubusercontent.comGitHubGitHub
cfu.zaproxy.orgUnknown
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
firefox.settings.services.mozilla.comUnknown
r10.o.lencr.orgUnknown
content-signature-2.cdn.mozilla.netUnknown
data.streamlit.ioUnknown
webhooks.fivetran.comUnknown
firefox-settings-attachments.cdn.mozilla.netUnknown
tel.zaproxy.orgUnknown
r11.o.lencr.orgUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
x.cp.wd.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
us-v20.events.data.microsoft.comMicrosoftMicrosoft
unitedstates.cp.wd.microsoft.comMicrosoftMicrosoft
storage.googleapis.comGoogleGoogle
check.trivy.devUnknown
fseeazasi4rqdij6hw2harq3.blob.core.windows.netUnknown
sum.golang.orgUnknown
release-assets.githubusercontent.comGitHubGitHub
releases.hashicorp.comHashiCorpHashiCorp
packages.microsoft.comMicrosoftMicrosoft
azure.archive.ubuntu.comUbuntuUbuntu
esm.ubuntu.comUbuntuUbuntu
evbgu32ymljjq7ar3zgaq674.blob.core.windows.netUnknown
repo.maven.apache.orgUnknown
api.sonarcloud.ioSonarSonar
sonarcloud.ioSonarSonar
scanner.sonarcloud.ioSonarSonar
analysis-sensorcache-eu-central-1-prod.s3.eu-central-1.amazonaws.comUnknown
example.comUnknown
capnproto.orgUnknown
static.rust-lang.orgUnknown
proxy.golang.orgGolang ProxyGolang Proxy
registry.npmjs.orgnpm Registrynpm Registry
api.osv.devUnknown
index.crates.ioUnknown
static.crates.ioUnknown
checkstyle.orgUnknown
crates.ioUnknown
packages.nautechsystems.ioUnknown
httpstat.usUnknown
indexer.dydx.tradeUnknown
api.binance.comUnknown
get.helm.shUnknown
us-docker.pkg.devUnknown
nodejs.orgUnknown
get.trivy.devUnknown
public.ecr.awsUnknown
d2glxqk2uabbnd.cloudfront.netUnknown
jxi77vh37xy7ngmxtab4fnpa.blob.core.windows.netUnknown
openaipublic.blob.core.windows.netUnknown
api.openai.comUnknown
indexer.v4testnet.dydx.exchangeUnknown
repo.hex.pmUnknown
builds.hex.pmUnknown
formulae.brew.shUnknown
eu-central-1-1.aws.cloud2.influxdata.comUnknown
coveralls.ioUnknown
hex.pmUnknown
telemetry.vercel.comUnknown
turbo-remote-cache.apps.01.cf.eu01.stackit.cloudUnknown
cdn.playwright.devUnknown
playwright.download.prss.microsoft.comMicrosoftMicrosoft
aus5.mozilla.orgUnknown
badge.fury.ioUnknown
d25lcipzij17d.cloudfront.netUnknown
gruppe.schwarzUnknown
it.schwarzUnknown
vueuse.orgUnknown
router.vuejs.orgUnknown
en.wikipedia.orgUnknown
fontsource.orgUnknown
www.npmjs.comUnknown
www.chartjs.orgUnknown
playground.onyx.schwarzUnknown
storybook.onyx.schwarzUnknown
demo.onyx.schwarzUnknown
vue-blueprint.schwarzUnknown
developer.mozilla.orgUnknown
edge.microsoft.comMicrosoftMicrosoft
copilot.microsoft.comMicrosoftMicrosoft
www.bing.comUnknown
edgeassetservice.azureedge.netUnknown
self.events.data.microsoft.comMicrosoftMicrosoft
cdn.jsdelivr.netUnknown
data.jsdelivr.comUnknown
edge-cloud-resource-static.azureedge.netUnknown
edge-mobile-static.azureedge.netUnknown
pixabay.comUnknown
pexels.comUnknown
unsplash.comUnknown
fonts.google.comUnknown
arc.msn.comUnknown
sass-lang.comUnknown
playwright.devUnknown
vitest.devUnknown
marketplace.visualstudio.comUnknown
eslint.orgUnknown
vuejs.orgUnknown