StepSecurity Logo
StepSecurity
LoginStart free
actions/github-script

actions/github-script

Write workflows scripting the GitHub API in JavaScript

GitHubGitHub Repository

4921 stars

Node.js

Node Action

Score updated 31 minutes ago

GitHub Actions security score

actions/github-script

Score

7/10

License

MIT License

Maintained

13 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

21 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 53376 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/github-script

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
github.comGitHubGitHub
uploads.github.comGitHubGitHub
c276-87-221-149-209.ngrok-free.appUnknown
smee.ioUnknown
api.cloudinary.comUnknown
app.terraform.ioUnknown
dc.services.visualstudio.comUnknown
api.cloudflare.comUnknown
workers.cloudflare.comUnknown
opensource.orgUnknown
nox.thea.codesUnknown
jmbde-python.readthedocs.ioUnknown
jitpack.ioUnknown
registry.npmjs.orgnpm Registrynpm Registry
packages.microsoft.comMicrosoftMicrosoft
azure.archive.ubuntu.comUbuntuUbuntu
esm.ubuntu.comUbuntuUbuntu
o26192.ingest.us.sentry.ioUnknown
versions.backstage.ioUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
cli.codecov.ioCodecovCodecov
keybase.ioUnknown
ingest.codecov.ioCodecovCodecov
webhook.siteUnknown
intel.webhook.office.comUnknown
release-assets.githubusercontent.comGitHubGitHub
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
astral.shUnknown
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
raw.githubusercontent.comGitHubGitHub
get.anchore.ioUnknown
fulcio.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
tuf-repo-cdn.sigstore.devSigstoreSigstore
tuf-repo.github.comGitHubGitHub
tmaproduction.blob.core.windows.netUnknown
cdn.playwright.devUnknown
playwright.download.prss.microsoft.comMicrosoftMicrosoft
production.cloudflare.docker.comDockerHubDockerHub
binaries.prisma.shUnknown
ci-preview-mail-news-worker.tattira120.workers.devUnknown
registry.npmjs.comUnknown
grype.anchore.ioUnknown
mirror.accum.seUnknown
proxy.golang.orgGolang ProxyGolang Proxy
storage.googleapis.comGoogleGoogle
redirector.gvt1.comUnknown
r5---sn-p5qlsn6s.gvt1.comUnknown
r4---sn-p5qs7nzr.gvt1.comUnknown
r3---sn-vgqsknde.gvt1.comUnknown
r2---sn-o097znzk.gvt1.comUnknown
r1---sn-vgqsrnld.gvt1.comUnknown
r1---sn-o097znzd.gvt1.comUnknown
r5---sn-p5qlsn6z.gvt1.comUnknown
configuration.apple.comUnknown
ocsp.digicert.comUnknown
bag.itunes.apple.comUnknown
mesu.apple.comUnknown
xp.apple.comUnknown
pancake.apple.comUnknown
swscan.apple.comUnknown
configuration.ls.apple.comUnknown
swallow.apple.comUnknown
ocsp2.apple.comUnknown
configuration-row-lb.apple.com.akadns.netUnknown
updates.cdn-apple.comUnknown
swdist.apple.comUnknown
settings-win.data.microsoft.comMicrosoftMicrosoft
incoming.telemetry.mozilla.orgUnknown
telemetry-incoming.r53-2.services.mozilla.comUnknown
dns.msftncsi.comUnknown
apple-relay.cloudflare.comUnknown
tas02.sls.update.microsoft.comMicrosoftMicrosoft
www.microsoft.comMicrosoftMicrosoft
fe2cr.update.microsoft.comMicrosoftMicrosoft
gdmf.apple.comUnknown
apple-relay.fastly-edge.comUnknown
ipcdn.apple.comUnknown
mask-api.icloud.comUnknown
metrics.icloud.comUnknown
fbs.smoot.apple.comUnknown
device-config.pcms.apple.comUnknown
configuration.apple.com.akadns.netUnknown
ocsp.sectigo.comUnknown
ecs.office.comUnknown
valid.apple.comUnknown
0.pool.ntp.orgUnknown
client.wns.windows.comUnknown
download.windowsupdate.comUnknown
s.mzstatic.comUnknown
fpinit.itunes.apple.comUnknown
sf-api-token-service.itunes.apple.comUnknown
assets-mercury.mzstatic.comUnknown
calendars.icloud.comUnknown
api.apple-cloudkit.comUnknown
gateway.icloud.comUnknown
api.apple-cloudkit.fe2.apple-dns.netUnknown
cds.apple.comUnknown
help.apple.comUnknown
apps.mzstatic.comUnknown
experiments.apple.comUnknown
mesu-cdn.origin-apple.com.akadns.netUnknown
e3528.dscg.akamaiedge.netUnknown
ocsp2.g.aaplimg.comUnknown
ocsp.usertrust.comUnknown
init.itunes.apple.comUnknown
swdist.apple.com.akadns.netUnknown
gspe1-ssl.ls.apple.comUnknown
amp-api.media.apple.comUnknown
telemetry.vercel.comUnknown
api.vercel.comUnknown
discordapp.comUnknown
prod.app-api.stepsecurity.ioUnknown
discord.comUnknown
swdist.g.aaplimg.comUnknown
geo.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
au.download.windowsupdate.comUnknown