StepSecurity Logo
StepSecurity
LoginStart free
actions/setup-python

actions/setup-python

Set up your GitHub Actions workflow with a specific version of Python

GitHubGitHub Repository

2135 stars

Node.js

Node Action

Score updated 2 days ago

GitHub Actions security score

actions/setup-python

Score

5/10

License

MIT License

Maintained

3 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2

Vulnerabilities

29 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 141184 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/setup-python

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
pypi.python.orgPython RegistryPython Registry
raw.githubusercontent.comGitHubGitHub
dc.services.visualstudio.comUnknown
auth.safetycli.comUnknown
esm.ubuntu.comUbuntuUbuntu
checkpoint-api.hashicorp.comUnknown
cdn01.quay.ioUnknown
quay.ioUnknown
charts.min.ioUnknown
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
release-assets.githubusercontent.comGitHubGitHub
downloads.python.orgUnknown
packages.microsoft.comMicrosoftMicrosoft
azure.archive.ubuntu.comUbuntuUbuntu
jenkins.jans.ioUnknown
global.endpoint.security.microsoft.comMicrosoftMicrosoft
cli.codecov.ioCodecovCodecov
keybase.ioUnknown
o26192.ingest.us.sentry.ioUnknown
repo.maven.apache.orgUnknown
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
x.cp.wd.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
unitedstates.cp.wd.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
check.trivy.devUnknown
astral.shUnknown
registry.npmjs.orgnpm Registrynpm Registry
git.gendocu.comUnknown
nodejs.orgUnknown
repository.apache.orgUnknown
api.gradio.appUnknown
checkip.amazonaws.comUnknown
openaipublic.blob.core.windows.netUnknown
download.qt.ioUnknown
ftp.fau.deUnknown
firmware.ardupilot.orgUnknown
docs.qgroundcontrol.comUnknown
qgroundcontrol.comUnknown
sources.debian.orgUnknown
api.launchpad.netUnknown
mirrors.20i.comUnknown
qt.mirror.constant.comUnknown
get.anchore.ioUnknown
fulcio.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
uploads.github.comGitHubGitHub
ocsp2.apple.comUnknown
api.apple-cloudkit.comUnknown
bag.itunes.apple.comUnknown
mask-api.icloud.comUnknown
metrics.icloud.comUnknown
gdmf.apple.comUnknown
device-config.pcms.apple.comUnknown
client.wns.windows.comUnknown
ocsp.digicert.comUnknown
configuration.ls.apple.comUnknown
swallow.apple.comUnknown
mesu.apple.comUnknown
fbs.smoot.apple.comUnknown
settings-win.data.microsoft.comMicrosoftMicrosoft
gist.github.comGitHubGitHub
configuration.apple.comUnknown
blob.bn9prdstrz04a.store.core.windows.netUnknown
dns.msftncsi.comUnknown
dns.googleUnknown
_dns.resolver.arpaUnknown
ocsp.sectigo.comUnknown
xp.apple.comUnknown
www.microsoft.comMicrosoftMicrosoft
incoming.telemetry.mozilla.orgUnknown
fs.microsoft.comMicrosoftMicrosoft
telemetry-incoming.r53-2.services.mozilla.comUnknown
api.apple-cloudkit.fe2.apple-dns.netUnknown
gateway.icloud.comUnknown
swscan.apple.comUnknown
swdist.apple.comUnknown
apple-relay.cloudflare.comUnknown
ipcdn.apple.comUnknown
cds.apple.comUnknown
apple-relay.fastly-edge.comUnknown
pancake.apple.comUnknown
oneocsp.microsoft.comMicrosoftMicrosoft
www.python.orgUnknown
ocsp2.globalsign.comUnknown
ocsp.globalsign.comUnknown
fe2cr.update.microsoft.comMicrosoftMicrosoft
download.windowsupdate.comUnknown
geo.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
au.download.windowsupdate.comUnknown
humb.apple.comUnknown
ocsp2.g.aaplimg.comUnknown
ocsp.comodoca.com.cdn.cloudflare.netUnknown
tas02.sls.update.microsoft.comMicrosoftMicrosoft
0.pool.ntp.orgUnknown
gspe1-ssl.ls.apple.comUnknown
login.live.comUnknown
s.mzstatic.comUnknown
configuration-row-lb.apple.com.akadns.netUnknown
updates.cdn-apple.comUnknown
xp-cdn-lb.itunes-apple.com.akadns.netUnknown
ocsp.edge.digicert.comUnknown
certs.apple.comUnknown
news-edge.apple.comUnknown
c.apple.newsUnknown
calendars.icloud.comUnknown
help.apple.comUnknown
gateway-oblivious.apple.comUnknown
valid.apple.comUnknown
mesu-cdn.origin-apple.com.akadns.netUnknown
swdist.apple.com.akadns.netUnknown
xp.itunes-apple.com.akadns.netUnknown
ipcdn-lb.apple.com.akadns.netUnknown
init.itunes.apple.comUnknown
kv501.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp501.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
publicassets.cdn-apple.comUnknown
kv801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
configuration.apple.com.akadns.netUnknown
experiments.apple.comUnknown
apps.mzstatic.comUnknown
ab.apple.com.akadns.netUnknown
ecs.office.comUnknown
slscr.update.microsoft.comMicrosoftMicrosoft
fe3cr.delivery.mp.microsoft.comMicrosoftMicrosoft
swscan-cdn.apple.com.akadns.netUnknown
assets-mercury.mzstatic.comUnknown
mobile.events.data.microsoft.comMicrosoftMicrosoft
fpinit.itunes.apple.comUnknown
unlinkability.apple.comUnknown
dap.pat-issuer.cloudflare.comUnknown
gdmf-ados.apple.comUnknown
e3528.dscg.akamaiedge.netUnknown
help.origin-apple.com.akadns.netUnknown
stocks-data-service.apple.comUnknown
api.smoot.apple.comUnknown
ocsp.comodoca.comUnknown
configuration.apple.com.edgekey.netUnknown
sf-api-token-service.itunes.apple.comUnknown
amp-api.media.apple.comUnknown
gsa.apple.comUnknown
ocsp.usertrust.comUnknown
xp.v.aaplimg.comUnknown
h3.apis.apple.map.fastly.netUnknown
ocsp2.apple.com.edgekey.netUnknown
adl.windows.comUnknown
gspe35-ssl.ls.apple.comUnknown
download.pytorch.orgUnknown
download-r2.pytorch.orgUnknown
releases.astral.shUnknown
iam.cloud.ibm.comUnknown
api.dataplatform.cloud.ibm.comUnknown
us-south.ml.cloud.ibm.comUnknown
huggingface.coUnknown
gsp-ssl.ls.apple.comUnknown
init-kt.apple.comUnknown
iadsdk.apple.comUnknown
stocks-edge.apple.comUnknown
configuration-lb.ls-apple.com.akadns.netUnknown
prod.app-api.stepsecurity.ioUnknown
setup.icloud.comUnknown
swdist.g.aaplimg.comUnknown
images-mercury.mzstatic.comUnknown
gdmf.v.aaplimg.comUnknown
is4-ssl.mzstatic.comUnknown
is3-ssl.mzstatic.comUnknown
is2-ssl.mzstatic.comUnknown
is5-ssl.mzstatic.comUnknown
mask.icloud.comUnknown