StepSecurity Logo
StepSecurity
LoginStart free
anchore/sbom-action/publish-sbom

anchore/sbom-action/publish-sbom

GitHub Action for creating software bill of materials using Syft.

GitHubGitHub Repository

242 stars

Node.js

Node Action

Maintained action available

Score updated 21 hours ago

GitHub Actions security score

anchore/sbom-action/publish-sbom

Score

6/10

License

Apache License 2.0

Maintained

29 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

19 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 61 open-source projects

Security Policy

security policy file detected

Networking Behavior of anchore/sbom-action/publish-sbom

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub