StepSecurity Logo
StepSecurity
LoginStart free
anchore/sbom-action

anchore/sbom-action

GitHub Action for creating software bill of materials using Syft.

GitHubGitHub Repository

242 stars

Node.js

Node Action

Maintained action available

Score updated 6 days ago

GitHub Actions security score

anchore/sbom-action

Score

8/10

License

Apache License 2.0

Maintained

30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

19 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 1648 open-source projects

Security Policy

security policy file detected

Networking Behavior of anchore/sbom-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
raw.githubusercontent.comGitHubGitHub
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
quay.ioUnknown
cdn03.quay.ioUnknown
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
api.github.comGitHubGitHub
cdn02.quay.ioUnknown
uploads.github.comGitHubGitHub
registry-1.docker.ioDockerHubDockerHub
index.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
release-assets.githubusercontent.comGitHubGitHub
us-v20.events.data.microsoft.comMicrosoftMicrosoft
get.anchore.ioUnknown
proxy.golang.orgGolang ProxyGolang Proxy
storage.googleapis.comGoogleGoogle
cdn01.quay.ioUnknown
us-west1-docker.pkg.devUnknown
sum.golang.orgUnknown
uksmanaged246.blob.core.windows.netUnknown
xp.itunes-apple.com.akadns.netUnknown
ipcdn.apple.comUnknown
392159838427.dkr.ecr.eu-west-1.amazonaws.comUnknown
mesu-cdn.origin-apple.com.akadns.netUnknown
valid.apple.comUnknown
ocsp2.apple.comUnknown
mask.icloud.comUnknown
mesu.apple.comUnknown
updates.cdn-apple.comUnknown
swdist.apple.com.akadns.netUnknown
swdist.apple.comUnknown
xp.apple.comUnknown
gdmf.apple.comUnknown
dns.msftncsi.comUnknown
mask-api.icloud.comUnknown
cds.apple.comUnknown
help.apple.comUnknown