StepSecurity Logo
StepSecurity
LoginStart free
actions/download-artifact

actions/download-artifact

GitHubGitHub Repository

1849 stars

Node.js

Node Action

Score updated 4 days ago

GitHub Actions security score

actions/download-artifact

Score

5/10

License

MIT License

Maintained

3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2

Vulnerabilities

31 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 66304 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/download-artifact

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
dc.services.visualstudio.comUnknown
agent.less.buildUnknown
binaries.sonarsource.comUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
x.cp.wd.microsoft.comMicrosoftMicrosoft
us-v20.events.data.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
get.buildpulse.ioUnknown
buildpulse-uploads.s3.amazonaws.comUnknown
cli.codecov.ioCodecovCodecov
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
storage.googleapis.comGoogleGoogle
2e62bcb97ef4babe79d26c047332c52a.r2.cloudflarestorage.comUnknown
storybook.js.orgUnknown
services.gradle.orgGradleGradle
github.comGitHubGitHub
release-assets.githubusercontent.comGitHubGitHub
plugins.gradle.orgGradleGradle
scans-in.gradle.comUnknown
plugins-artifacts.gradle.orgGradleGradle
repo.maven.apache.orgUnknown
api.adoptium.netUnknown
check.trivy.devUnknown
monitoring.us-east-1.amazonaws.comUnknown
packages.microsoft.comMicrosoftMicrosoft
fulcio.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
ghcr.ioGitHubGitHub
mobile.events.data.microsoft.comMicrosoftMicrosoft
settings-win.data.microsoft.comMicrosoftMicrosoft
configuration.ls.apple.comUnknown
news-edge.apple.comUnknown
0.pool.ntp.orgUnknown
c.apple.newsUnknown
dns.msftncsi.comUnknown
s.mzstatic.comUnknown
fpinit.itunes.apple.comUnknown
sf-api-token-service.itunes.apple.comUnknown
init.itunes.apple.comUnknown
bag.itunes.apple.comUnknown
mesu.apple.comUnknown
swscan.apple.comUnknown
swdist.apple.comUnknown
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
fbs.smoot.apple.comUnknown
metrics.icloud.comUnknown
ocsp2.apple.comUnknown
ocsp2.g.aaplimg.comUnknown
pancake.apple.comUnknown
geo.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
au.download.windowsupdate.comUnknown
ocsp.sectigo.comUnknown
download.windowsupdate.comUnknown
apple-relay.cloudflare.comUnknown
swallow.apple.comUnknown
calendars.icloud.comUnknown
gateway.icloud.comUnknown
init-kt.apple.comUnknown
cds.apple.comUnknown
help.apple.comUnknown
configuration.apple.comUnknown
login.live.comUnknown
fe3cr.delivery.mp.microsoft.comMicrosoftMicrosoft
kv601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
incoming.telemetry.mozilla.orgUnknown
ocsp.digicert.comUnknown
telemetry-incoming.r53-2.services.mozilla.comUnknown
configuration-row-lb.apple.com.akadns.netUnknown
xp.apple.comUnknown
gsa.apple.comUnknown
client.wns.windows.comUnknown
oneocsp.microsoft.comMicrosoftMicrosoft
fe2cr.update.microsoft.comMicrosoftMicrosoft
ipcdn.apple.comUnknown
experiments.apple.comUnknown
apps.mzstatic.comUnknown
mask-api.icloud.comUnknown
gdmf.apple.comUnknown
api.apple-cloudkit.comUnknown
gsp-ssl.ls.apple.comUnknown
gspe1-ssl.ls.apple.comUnknown
updates.cdn-apple.comUnknown
humb.apple.comUnknown
device-config.pcms.apple.comUnknown
assets-mercury.mzstatic.comUnknown
dns.googleUnknown
_dns.resolver.arpaUnknown
ocsp.usertrust.comUnknown
build-cloud.docker.comUnknown
auth.docker.ioDockerHubDockerHub
amp-api.media.apple.comUnknown
prod.app-api.stepsecurity.ioUnknown
api.apple-cloudkit.fe2.apple-dns.netUnknown
valid.apple.comUnknown
us-docker.pkg.devUnknown
mesu-cdn.origin-apple.com.akadns.netUnknown
stocks-data-service.apple.comUnknown
images-mercury.mzstatic.comUnknown
swdist.g.aaplimg.comUnknown
lcdn-locator.apple.comUnknown
blob.bn9prdstrz04a.store.core.windows.netUnknown
xp.itunes-apple.com.akadns.netUnknown
configuration.apple.com.akadns.netUnknown
stocks-edge.apple.comUnknown
unlinkability.apple.comUnknown
tas02.sls.update.microsoft.comMicrosoftMicrosoft
www.microsoft.comMicrosoftMicrosoft
quay.ioUnknown
cdn01.quay.ioUnknown
raw.githubusercontent.comGitHubGitHub
mask.icloud.comUnknown
ipcdn-lb.apple.com.akadns.netUnknown
ecs.office.comUnknown
fs.microsoft.comMicrosoftMicrosoft
gdmf.v.aaplimg.comUnknown
slscr.update.microsoft.comMicrosoftMicrosoft
xp.v.aaplimg.comUnknown
sts.googleapis.comGoogleGoogle
www.keil.comUnknown
sadevicepacksdqaus.blob.core.windows.netUnknown
keilpack.azureedge.netUnknown
license.cloud.iar.comUnknown
mcuxpresso.nxp.comUnknown
sadevicepacksprodus.blob.core.windows.netUnknown
telemetry.prd.sdc.cloud.iar.comUnknown
status.geotrust.comUnknown
weather-edge.apple.comUnknown
api.smoot.apple.comUnknown
ocsp.comodoca.comUnknown
sequoia.cdn-apple.comUnknown
xp-cdn-lb.itunes-apple.com.akadns.netUnknown
apple-relay.fastly-edge.comUnknown
cafe.github.comGitHubGitHub
adl.windows.comUnknown
help.origin-apple.com.akadns.netUnknown
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
index.crates.ioUnknown
ocsp2.globalsign.comUnknown
static.crates.ioUnknown
telemetry.visualstudio.microsoft.comMicrosoftMicrosoft
ocsp.globalsign.comUnknown
cdn.smoot.apple.comUnknown
e3528.dscg.akamaiedge.netUnknown
configuration.apple.com.edgekey.netUnknown
tsfe.trafficshaping.dsp.mp.microsoft.comMicrosoftMicrosoft
dap.pat-issuer.cloudflare.comUnknown
time.windows.comUnknown
gateway-oblivious.apple.comUnknown
cp501.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
gspe35-ssl.ls.apple.comUnknown
cdn-h3.g.aaplimg.comUnknown
1a.au.download.windowsupdate.comUnknown
displaycatalog.mp.microsoft.comMicrosoftMicrosoft
tas01.cwsapp.update.microsoft.comMicrosoftMicrosoft
1d.tlu.dl.delivery.mp.microsoft.comMicrosoftMicrosoft
registry.access.redhat.comRedhat
cdn-ubi.redhat.comRedhat
gerrit.fd.ioUnknown
nexus3.o-ran-sc.orgUnknown
get.anchore.ioUnknown
proxy.golang.orgGolang ProxyGolang Proxy
lf-opendaylight.atlassian.netUnknown
cache.agilebits.comUnknown
uploads.github.comGitHubGitHub
static.rust-lang.orgUnknown
jira.o-ran-sc.orgUnknown
endoflife.dateUnknown
deb.debian.orgUnknown
esm.ubuntu.comUbuntuUbuntu
dl.google.comGoogleGoogle
ftp.mozilla.orgUnknown
jira.onap.orgUnknown
www.google.comUnknown
build.automotivelinux.orgUnknown
upload.pypi.orgPython RegistryPython Registry
jenkins.o-ran-sc.orgUnknown
repo1.maven.orgUnknown
mirror.gcr.ioUnknown
weatherkit.apple.comUnknown
pkg-containers.githubusercontent.comGitHubGitHub
cf.iadsdk.apple.comUnknown
v1.ta2.fe2cr.update.microsoft.comMicrosoftMicrosoft
gateway.fe2.apple-dns.netUnknown
media.githubusercontent.comGitHubGitHub
chocolatey.orgUnknown
www.bestpractices.devUnknown