StepSecurity Logo
StepSecurity
LoginStart free
actions/download-artifact

actions/download-artifact

GitHubGitHub Repository

1810 stars

Node.js

Node Action

Score updated 2 days ago

GitHub Actions security score

actions/download-artifact

Score

7/10

License

MIT License

Maintained

25 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

30 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 90496 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/download-artifact

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
dc.services.visualstudio.comUnknown
agent.less.buildUnknown
binaries.sonarsource.comUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
x.cp.wd.microsoft.comMicrosoftMicrosoft
us-v20.events.data.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
get.buildpulse.ioUnknown
buildpulse-uploads.s3.amazonaws.comUnknown
cli.codecov.ioCodecovCodecov
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
storage.googleapis.comGoogleGoogle
2e62bcb97ef4babe79d26c047332c52a.r2.cloudflarestorage.comUnknown
storybook.js.orgUnknown
services.gradle.orgGradleGradle
github.comGitHubGitHub
release-assets.githubusercontent.comGitHubGitHub
plugins.gradle.orgGradleGradle
scans-in.gradle.comUnknown
plugins-artifacts.gradle.orgGradleGradle
repo.maven.apache.orgUnknown
api.adoptium.netUnknown
check.trivy.devUnknown
monitoring.us-east-1.amazonaws.comUnknown
packages.microsoft.comMicrosoftMicrosoft
fulcio.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
ghcr.ioGitHubGitHub
mobile.events.data.microsoft.comMicrosoftMicrosoft
settings-win.data.microsoft.comMicrosoftMicrosoft
configuration.ls.apple.comUnknown
news-edge.apple.comUnknown
0.pool.ntp.orgUnknown
c.apple.newsUnknown
dns.msftncsi.comUnknown
s.mzstatic.comUnknown
fpinit.itunes.apple.comUnknown
sf-api-token-service.itunes.apple.comUnknown
init.itunes.apple.comUnknown
bag.itunes.apple.comUnknown
mesu.apple.comUnknown
swscan.apple.comUnknown
swdist.apple.comUnknown
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
fbs.smoot.apple.comUnknown
metrics.icloud.comUnknown
ocsp2.apple.comUnknown
ocsp2.g.aaplimg.comUnknown
pancake.apple.comUnknown
geo.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
au.download.windowsupdate.comUnknown
ocsp.sectigo.comUnknown
download.windowsupdate.comUnknown
apple-relay.cloudflare.comUnknown
swallow.apple.comUnknown
calendars.icloud.comUnknown
gateway.icloud.comUnknown
init-kt.apple.comUnknown
cds.apple.comUnknown
help.apple.comUnknown
configuration.apple.comUnknown
login.live.comUnknown
fe3cr.delivery.mp.microsoft.comMicrosoftMicrosoft
kv601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
incoming.telemetry.mozilla.orgUnknown
ocsp.digicert.comUnknown
telemetry-incoming.r53-2.services.mozilla.comUnknown
configuration-row-lb.apple.com.akadns.netUnknown
xp.apple.comUnknown
gsa.apple.comUnknown
client.wns.windows.comUnknown
oneocsp.microsoft.comMicrosoftMicrosoft
fe2cr.update.microsoft.comMicrosoftMicrosoft
ipcdn.apple.comUnknown
experiments.apple.comUnknown
apps.mzstatic.comUnknown
mask-api.icloud.comUnknown
gdmf.apple.comUnknown
api.apple-cloudkit.comUnknown
gsp-ssl.ls.apple.comUnknown
gspe1-ssl.ls.apple.comUnknown
updates.cdn-apple.comUnknown
humb.apple.comUnknown
device-config.pcms.apple.comUnknown
assets-mercury.mzstatic.comUnknown
dns.googleUnknown
_dns.resolver.arpaUnknown
ocsp.usertrust.comUnknown
build-cloud.docker.comUnknown
auth.docker.ioDockerHubDockerHub
amp-api.media.apple.comUnknown
prod.app-api.stepsecurity.ioUnknown
api.apple-cloudkit.fe2.apple-dns.netUnknown
valid.apple.comUnknown
us-docker.pkg.devUnknown