actions/upload-artifact

actions/upload-artifact

GitHubGithub Repository

3491 stars

Node.js

Node Action

Updated 2 days ago

GitHub Actions security score

actions/upload-artifact

Score

7/10

License

MIT License

Maintained

8 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 6

Vulnerabilities

6 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 10904 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/upload-artifact

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
scans-in.gradle.comUnknown
Unknown
telemetry.redwoodjs.comUnknown
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
quark.quantumparticle.ioUnknown
cdnjs.cloudflare.comUnknown
fonts.gstatic.comUnknown
api.github.comGitHubGitHub
fonts.googleapis.comGoogleGoogle
cdn.jsdelivr.netUnknown
dc.services.visualstudio.comUnknown
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
edge.pkg.stUnknown
quay.ioUnknown
cdn03.quay.ioUnknown
api.codecov.ioCodecovCodecov
storage.googleapis.comGoogleGoogle
subnet.min.ioUnknown
api.linode.comUnknown
epss.cyentia.comUnknown
www.cisa.govCISACISA
www.fleetdm.comUnknown
fleetdm.comUnknown
proxy.golang.orgGolang ProxyGolang Proxy
sum.golang.orgUnknown
tuf.fleetctl.comUnknown
www.debian.orgUnknown
gcr.ioUnknown
dl.min.ioUnknown
security-metadata.canonical.comUnknown
cdn.fwupd.orgUnknown
charts.jetstack.ioUnknown
open-policy-agent.github.ioUnknown
learn.microsoft.comMicrosoftMicrosoft
production.cloudflare.docker.comDockerHubDockerHub
mdmenrollment.apple.comUnknown
region1.v2.argotunnel.comUnknown
pkg-containers.githubusercontent.comGitHubGitHub
raw.githubusercontent.comGitHubGitHub
www.redhat.comRedhat
update.traefik.ioUnknown
region2.v2.argotunnel.comUnknown
objects-origin.githubusercontent.comGitHubGitHub
pypi.orgPython RegistryPython Registry
esm.ubuntu.comUbuntuUbuntu
formulae.brew.shUnknown
security.access.redhat.comRedhat
api.ipify.orgUnknown
vpp.itunes.apple.comUnknown
repo.maven.apache.orgUnknown
packages.microsoft.comMicrosoftMicrosoft
security.ubuntu.comUbuntuUbuntu
archive.ubuntu.comUbuntuUbuntu
httpstat.usUnknown
deb.debian.orgUnknown
jitpack.ioUnknown
ratifyacrac47.azurecr.ioUnknown
ratify-aks-ratify-e2e-5810-daae1e-nntu4zhj.hcp.westus2.azmk8s.ioUnknown
updates.fleetdm.comUnknown
westus2.data.mcr.microsoft.comMicrosoftMicrosoft
eastus.data.mcr.microsoft.comMicrosoftMicrosoft
mcr.microsoft.comMicrosoftMicrosoft
centralus.data.mcr.microsoft.comMicrosoftMicrosoft
registry.npmjs.orgnpm Registrynpm Registry
mirrors.almalinux.orgUnknown
azure.repo.almalinux.orgUnknown
mirrors.rockylinux.orgUnknown
us.mirrors.cicku.meUnknown
distro.ibiblio.orgUnknown
mirror.chpc.utah.eduUnknown
prod-registry-k8s-io-us-east-1.s3.dualstack.us-east-1.amazonaws.comUnknown
mirrors.rit.eduUnknown
rocky-linux-europe-west3.production.gcp.mirrors.ctrliq.cloudUnknown
ftp.fau.deUnknown
mirrors.xtom.deUnknown
checkpoint.prisma.ioUnknown
epss.empiricalsecurity.comUnknown
mirror.cs.vt.eduUnknown
westus2.azure.repo.almalinux.orgUnknown
dl.rockylinux.orgUnknown
mirror.siena.eduUnknown
cdn01.quay.ioUnknown
cli.codecov.ioCodecovCodecov
ingest.codecov.ioCodecovCodecov
o26192.ingest.us.sentry.ioUnknown
westeurope.api.playwright.microsoft.comMicrosoftMicrosoft
browser.playwright.microsoft.comMicrosoftMicrosoft