actions/upload-artifact
GitHub Actions security score
actions/upload-artifact | |
---|---|
Score | 7/10 |
License | MIT License |
Maintained | 8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6 |
Vulnerabilities | 6 existing vulnerabilities detected |
Branch protection | branch protection not enabled on development/release branches |
Manual code review | - |
Secure publishing | - |
Signed commits | - |
Automated security tools | - |
Popular | Used by 10904 open-source projects |
Security Policy | security policy file detected |
Networking Behavior of actions/upload-artifact
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
Popular DestinationUnknown Destination
Network Destination | Owner |
---|---|
scans-in.gradle.com | Unknown |
Unknown | |
telemetry.redwoodjs.com | Unknown |
registry-1.docker.io | |
auth.docker.io | |
quark.quantumparticle.io | Unknown |
cdnjs.cloudflare.com | Unknown |
fonts.gstatic.com | Unknown |
api.github.com | ![]() |
fonts.googleapis.com | |
cdn.jsdelivr.net | Unknown |
dc.services.visualstudio.com | Unknown |
github.com | ![]() |
objects.githubusercontent.com | ![]() |
edge.pkg.st | Unknown |
quay.io | Unknown |
cdn03.quay.io | Unknown |
api.codecov.io | |
storage.googleapis.com | |
subnet.min.io | Unknown |
api.linode.com | Unknown |
epss.cyentia.com | Unknown |
www.cisa.gov | |
www.fleetdm.com | Unknown |
fleetdm.com | Unknown |
proxy.golang.org | |
sum.golang.org | Unknown |
tuf.fleetctl.com | Unknown |
www.debian.org | Unknown |
gcr.io | Unknown |
dl.min.io | Unknown |
security-metadata.canonical.com | Unknown |
cdn.fwupd.org | Unknown |
charts.jetstack.io | Unknown |
open-policy-agent.github.io | Unknown |
learn.microsoft.com | |
production.cloudflare.docker.com | |
mdmenrollment.apple.com | Unknown |
region1.v2.argotunnel.com | Unknown |
pkg-containers.githubusercontent.com | ![]() |
raw.githubusercontent.com | ![]() |
www.redhat.com | Redhat |
update.traefik.io | Unknown |
region2.v2.argotunnel.com | Unknown |
objects-origin.githubusercontent.com | ![]() |
pypi.org | |
esm.ubuntu.com | |
formulae.brew.sh | Unknown |
security.access.redhat.com | Redhat |
api.ipify.org | Unknown |
vpp.itunes.apple.com | Unknown |
repo.maven.apache.org | Unknown |
packages.microsoft.com | |
security.ubuntu.com | |
archive.ubuntu.com | |
httpstat.us | Unknown |
deb.debian.org | Unknown |
jitpack.io | Unknown |
ratifyacrac47.azurecr.io | Unknown |
ratify-aks-ratify-e2e-5810-daae1e-nntu4zhj.hcp.westus2.azmk8s.io | Unknown |
updates.fleetdm.com | Unknown |
westus2.data.mcr.microsoft.com | |
eastus.data.mcr.microsoft.com | |
mcr.microsoft.com | |
centralus.data.mcr.microsoft.com | |
registry.npmjs.org | |
mirrors.almalinux.org | Unknown |
azure.repo.almalinux.org | Unknown |
mirrors.rockylinux.org | Unknown |
us.mirrors.cicku.me | Unknown |
distro.ibiblio.org | Unknown |
mirror.chpc.utah.edu | Unknown |
prod-registry-k8s-io-us-east-1.s3.dualstack.us-east-1.amazonaws.com | Unknown |
mirrors.rit.edu | Unknown |
rocky-linux-europe-west3.production.gcp.mirrors.ctrliq.cloud | Unknown |
ftp.fau.de | Unknown |
mirrors.xtom.de | Unknown |
checkpoint.prisma.io | Unknown |
epss.empiricalsecurity.com | Unknown |
mirror.cs.vt.edu | Unknown |
westus2.azure.repo.almalinux.org | Unknown |
dl.rockylinux.org | Unknown |
mirror.siena.edu | Unknown |
cdn01.quay.io | Unknown |
cli.codecov.io | |
ingest.codecov.io | |
o26192.ingest.us.sentry.io | Unknown |
westeurope.api.playwright.microsoft.com | |
browser.playwright.microsoft.com |