actions/github-script
Write workflows scripting the GitHub API in JavaScript
GitHub Actions security score
actions/github-script | |
---|---|
Score | 8/10 |
License | MIT License |
Maintained | 10 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10 |
Vulnerabilities | 4 existing vulnerabilities detected |
Branch protection | branch protection is not maximal on development and all release branches |
Manual code review | - |
Secure publishing | - |
Signed commits | - |
Automated security tools | - |
Popular | Used by 2256 open-source projects |
Security Policy | security policy file detected |
Networking Behavior of actions/github-script
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
Popular DestinationUnknown Destination
Network Destination | Owner |
---|---|
api.github.com | ![]() |
github.com | ![]() |
uploads.github.com | ![]() |
Unknown | |
c276-87-221-149-209.ngrok-free.app | Unknown |
smee.io | Unknown |
cdn.fwupd.org | Unknown |
api.cloudinary.com | Unknown |
app.terraform.io | Unknown |
dc.services.visualstudio.com | Unknown |
api.cloudflare.com | Unknown |
workers.cloudflare.com | Unknown |
opensource.org | Unknown |
nox.thea.codes | Unknown |
jmbde-python.readthedocs.io | Unknown |
jitpack.io | Unknown |
registry.npmjs.org | |
packages.microsoft.com | |
azure.archive.ubuntu.com | |
esm.ubuntu.com |