actions/checkout

actions/checkout

Action for checking out a repo

GitHubGitHub Repository

7276 stars

Node.js

Node Action

Score updated 7 days ago

GitHub Actions security score

actions/checkout

Score

8/10

License

MIT License

Maintained

4 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3

Vulnerabilities

1 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 964608 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/checkout

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
github.comGitHubGitHub
skia.googlesource.comUnknown
gcr.ioUnknown
boringssl.googlesource.comUnknown
r8.googlesource.comUnknown
git.kernel.dkUnknown
api.github.comGitHubGitHub
github-cloud.githubusercontent.comGitHubGitHub
yum.oracle.comUnknown
mirrors.vcea.wsu.eduUnknown
d2lzkl7pfhq30w.cloudfront.netUnknown
mirrors.wcupa.eduUnknown
atl.mirrors.knownhost.comUnknown
chromium.googlesource.comUnknown
patch-diff.githubusercontent.comGitHubGitHub
instrumentation-telemetry-intake.datadoghq.comUnknown
powitni3dvag4e3vfsuxwbdl.blob.core.windows.netUnknown
auth.safetycli.comUnknown
api.securityscorecards.devUnknown
scans-in.gradle.comUnknown
repos.eggycrew.comUnknown
ftp-nyc.osuosl.orgUnknown
mirror.umd.eduUnknown
nnenix.mm.fcix.netUnknown
ix-denver.mm.fcix.netUnknown
dc.services.visualstudio.comUnknown
sum.golang.orgUnknown
ipfs-adebp.gke-europe.settlemint.comUnknown
objects-origin.githubusercontent.comGitHubGitHub
ipfs-ws.neaweb.chUnknown
ipfs-swarm.greyh.atUnknown
home.pathin.meUnknown
openthread.ioUnknown
ipfs.axlabs.netUnknown
checkpoint-cn.yeaosound.comUnknown
telemetry.redwoodjs.comUnknown
srv.nullob.siUnknown
config.datadoghq.comUnknown
ipfs-node.pcdn.svconcloud.comUnknown
ipfs-c9a6p.settlemint.comUnknown
github.com.kktgveqfb1qudcmjlb3z23h2tb.xx.internal.cloudapp.netUnknown
dweb.quartzbear.linkUnknown
am6.bootstrap.libp2p.ioUnknown
ipfs-store-48eep.settlemint.comUnknown
home.xupernode.comUnknown
ipfs-store-3d9ep.settlemint.comUnknown
sv16.bootstrap.libp2p.ioUnknown
sg1.bootstrap.libp2p.ioUnknown
ipfs1-8c58p.aks-middleeast.settlemint.comUnknown
microsoft.comMicrosoftMicrosoft
packages.microsoft.comMicrosoftMicrosoft
va1.bootstrap.libp2p.ioUnknown
se1.files.someguy123.comUnknown
ipfs-92a0p.settlemint.comUnknown
qrze66qtsvxvfqere2mfdeot.blob.core.windows.netUnknown
aab76adad815848ca82122392d46393c-1873381457.us-east-2.elb.amazonaws.comUnknown
gitlab.comGitLabGitLab
2dg2rikggido7fysjhd7mr5c.blob.core.windows.netUnknown
t2g5a7hsasfeeerv7pdgpygo.blob.core.windows.netUnknown
istanbul.le-space.deUnknown
sony-bank-development-ipfs-1-36dfp.gke-japan.settlemint.comUnknown
checkpoint-hk.ipns.networkUnknown
checkpoint-hk.yeaosound.comUnknown
a2a4c5c095f8f4421ae16786a4865406-692485639.us-east-2.elb.amazonaws.comUnknown
repo.maven.apache.orgUnknown
containers.pkg.github.comGitHubGitHub
datapod-ws.gdev.1000i100.frUnknown
gdev.1000i100.frUnknown
s3zwo47y6v6ynwdzeq42glrv.blob.core.windows.netUnknown
greenbond.esUnknown
ipfs-store-cfc9p.settlemint.comUnknown
nft-ipfs-d9e4p.settlemint.comUnknown
ipfs-a84aap.gke-europe-staging.settlemint.comUnknown
atd-ipfs-1-62d0cp.gke-europe.settlemint.comUnknown
ipfs.22336699.xyzUnknown
ipfs-1-212eep.gke-europe-staging.settlemint.comUnknown
threadgroup.orgUnknown
link.springer.comUnknown
ipns-kubo-2.vin1.filebase.ioUnknown
pmu-skat-ipfs-7541cp.gke-europe-staging.settlemint.comUnknown
p2p.gke-middleeast.settlemint.comUnknown
objects.githubusercontent.comGitHubGitHub
ipns-kubo-0.vin1.filebase.ioUnknown
ipns-kubo-1.vin1.filebase.ioUnknown
git.ioUnknown
builds.dotnet.microsoft.comMicrosoftMicrosoft
kore.peelvalley.com.auUnknown
external1.ddns.peelvalley.com.auUnknown
cli.codecov.ioCodecovCodecov
media.laserlewdude.comUnknown
crates.ioUnknown
home.m.foilen.comUnknown
ipfs-swarm.fxhash2.xyzUnknown
112-82-110-25.k51qzi5uqu5dmj0y7896i0mxl2h5lyqs9up6duhlula4hsf6mxpfvjyesahrp5.libp2p.directUnknown
esm.ubuntu.comUbuntuUbuntu
d-gj2h7tnxlh.execute-api.us-west-2.amazonaws.comUnknown
amazon-ssm-us-west-2.s3.us-west-2.amazonaws.comUnknown
s3.us-west-2.amazonaws.comUnknown
ec2.us-west-2.amazonaws.comUnknown
arxiv.orgUnknown
dns.googleUnknown
api0.prismacloud.ioUnknown
ec2.us-east-1.amazonaws.comUnknown
pypi.orgPython RegistryPython Registry
static.rust-lang.orgUnknown
prtcacprodeus2file7.blob.core.windows.netUnknown
golang.orgUnknown
gk2hacprodeus1file7.blob.core.windows.netUnknown
dotnetbuilds.azureedge.netUnknown
raw.githubusercontent.comGitHubGitHub
api.deps.devUnknown
changelogs.ubuntu.comUbuntuUbuntu
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
canonical-bos01.cdn.snapcraftcontent.comUnknown
conda.anaconda.orgUnknown
prefix.devUnknown
packages.prefix.devUnknown
shards.prefix.devUnknown
uploads.github.comGitHubGitHub
registry.npmjs.orgnpm Registrynpm Registry
binaries.prisma.shUnknown
checkpoint.prisma.ioUnknown
telemetry.vercel.comUnknown
telemetry.nextjs.orgUnknown
aka.msUnknown
releases.nixos.orgUnknown
models.github.aiUnknown
azure.archive.ubuntu.comUbuntuUbuntu
release-assets.githubusercontent.comGitHubGitHub
x.cp.wd.microsoft.comMicrosoftMicrosoft
global.endpoint.security.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
us-v20.events.data.microsoft.comMicrosoftMicrosoft
unitedstates.x.cp.wd.microsoft.comMicrosoftMicrosoft
unitedstates.cp.wd.microsoft.comMicrosoftMicrosoft
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
proxy.golang.orgGolang ProxyGolang Proxy
storage.googleapis.comGoogleGoogle
check.trivy.devUnknown
registry.access.redhat.comRedhat
cdn01.quay.ioUnknown
cdn-ubi.redhat.comRedhat
mirror.gcr.ioUnknown
get.anchore.ioUnknown
dl.k8s.ioUnknown
cdn.dl.k8s.ioUnknown
fulcio.sigstore.devSigstoreSigstore
index.docker.ioDockerHubDockerHub
www.bestpractices.devUnknown
oss-fuzz-build-logs.storage.googleapis.comGoogleGoogle
tuf-repo-cdn.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
api.osv.devUnknown
plugins.gradle.orgGradleGradle
repo.gradle.orgGradleGradle
jcenter.bintray.comUnknown
downloads.gradle.orgGradleGradle
cdn.azul.comUnknown
gds.oracle.comUnknown
caffeine.gradle-enterprise.cloudUnknown
services.gradle.orgGradleGradle
api.foojay.ioUnknown
repo1.maven.orgUnknown
schemastore.orgUnknown
oss.sonatype.orgUnknown
plugins-artifacts.gradle.orgGradleGradle
download.oracle.comUnknown
centralus.data.mcr.microsoft.comMicrosoftMicrosoft
mcr.microsoft.comMicrosoftMicrosoft
westus2.data.mcr.microsoft.comMicrosoftMicrosoft
westus.data.mcr.microsoft.comMicrosoftMicrosoft
o1.ingest.sentry.ioUnknown
dashboard.snapcraft.ioUnknown
releases.hashicorp.comHashiCorpHashiCorp
checkpoint-api.hashicorp.comUnknown
api.scorecard.devUnknown
get.helm.shUnknown
files.pythonhosted.orgPython RegistryPython Registry
services.nvd.nist.govNISTNIST
api.vulncheck.comUnknown
mxirhoir1bkom.mrap.accesspoint.s3-global.amazonaws.comUnknown
npm.pkg.github.comGitHubGitHub
pkg-npm.githubusercontent.comGitHubGitHub
nodejs.orgUnknown
get.buildpulse.ioUnknown
buildpulse-uploads.s3.amazonaws.comUnknown
storybook.js.orgUnknown
cgr.devUnknown
index.rubygems.orgRubyGemsRubyGems
rubygems.orgRubyGemsRubyGems
ortelius.github.ioUnknown
www.google.comUnknown
releases.bazel.buildUnknown
bcr.bazel.buildUnknown
fonts.googleapis.comGoogleGoogle
fonts.gstatic.comUnknown
golangci-lint.runUnknown
mirror.bazel.buildUnknown
public.ecr.awsUnknown
d2glxqk2uabbnd.cloudfront.netUnknown
kubernetesjsonschema.devUnknown
quay.ioUnknown
dl.min.ioUnknown
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
sts.googleapis.comGoogleGoogle
iamcredentials.googleapis.comGoogleGoogle
us-west1-docker.pkg.devUnknown
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
debian.map.fastlydns.netUnknown
sp1.succinct.xyzUnknown
index.crates.ioUnknown
static.crates.ioUnknown
sp1-circuits.s3.us-east-2.amazonaws.comUnknown
gist.github.comGitHubGitHub
mise.jdx.devUnknown
keybase.ioUnknown
ssm.us-east-1.amazonaws.comUnknown
7-72-2-flare.agent.datadoghq.comUnknown
archive.ubuntu.comUbuntuUbuntu
sh.rustup.rsUnknown
security.ubuntu.comUbuntuUbuntu
logs.us-east-1.amazonaws.comUnknown
ec2messages.us-east-1.amazonaws.comUnknown
transfer.xethub.hf.coUnknown
huggingface.coUnknown
api.gradio.appUnknown