StepSecurity Logo
StepSecurity
LoginStart free
codecov/codecov-action

codecov/codecov-action

GitHub Action that uploads coverage to Codecov :open_umbrella:

GitHubGitHub Repository

1686 stars

Composite

Maintained action available

Score updated 2 days ago

Composite Action Details

Pinnable

Yes

GitHub Actions security score

codecov/codecov-action

Score

9/10

License

MIT License

Maintained

10 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 8

Vulnerabilities

0 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 70624 open-source projects

Security Policy

security policy file detected

Networking Behavior of codecov/codecov-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
uploader.codecov.ioCodecovCodecov
storage.googleapis.comGoogleGoogle
cli.codecov.ioCodecovCodecov
api.codecov.ioCodecovCodecov
codecov.ioCodecovCodecov
api.github.comGitHubGitHub
github.comGitHubGitHub
crates.ioUnknown
static.crates.ioUnknown
oss-fuzz-build-logs.storage.googleapis.comGoogleGoogle
repo1.maven.orgUnknown
testnet.mirrornode.hedera.comUnknown
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
repo.maven.apache.orgUnknown
elide-snapshots.storage-download.googleapis.comGoogleGoogle
osv-vulnerabilities.storage.googleapis.comGoogleGoogle
ingest.codecov.ioCodecovCodecov
keybase.ioUnknown
o26192.ingest.us.sentry.ioUnknown
us-v20.events.data.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
global.endpoint.security.microsoft.comMicrosoftMicrosoft
unitedstates.cp.wd.microsoft.comMicrosoftMicrosoft
release-assets.githubusercontent.comGitHubGitHub
ihub-pub.testspace.comUnknown
checkpoint-api.hashicorp.comUnknown
releases.hashicorp.comHashiCorpHashiCorp
registry.terraform.ioUnknown
nodejs.orgUnknown
binaries.prisma.shUnknown
pool.ntp.orgUnknown
pypi.orgPython RegistryPython Registry
mask-api.icloud.comUnknown
configuration.ls.apple.comUnknown
ocsp.sectigo.comUnknown
mesu.apple.comUnknown
bag.itunes.apple.comUnknown
configuration.apple.comUnknown
pancake.apple.comUnknown
metrics.icloud.comUnknown
device-config.pcms.apple.comUnknown
gdmf.apple.comUnknown
ipcdn.apple.comUnknown
weatherkit.apple.comUnknown
apple-relay.fastly-edge.comUnknown
api.apple-cloudkit.comUnknown
ocsp2.apple.comUnknown
valid.apple.comUnknown
xp.apple.comUnknown
ab.apple.com.akadns.netUnknown
s.mzstatic.comUnknown
experiments.apple.comUnknown
help.apple.comUnknown
apple-relay.cloudflare.comUnknown
configuration-row-lb.apple.com.akadns.netUnknown
h3.apis.apple.map.fastly.netUnknown
cds.apple.comUnknown
updates.cdn-apple.comUnknown
ocsp.digicert.comUnknown
swallow.apple.comUnknown
0.pool.ntp.orgUnknown
fbs.smoot.apple.comUnknown
swscan.apple.comUnknown
packages.microsoft.comMicrosoftMicrosoft
gateway.icloud.comUnknown
fpinit.itunes.apple.comUnknown
sf-api-token-service.itunes.apple.comUnknown
apps.mzstatic.comUnknown
init.itunes.apple.comUnknown
ocsp2.g.aaplimg.comUnknown
tether.edge.appleUnknown
proxy.safebrowsing.appleUnknown
www.microsoft.comMicrosoftMicrosoft
dns.msftncsi.comUnknown
incoming.telemetry.mozilla.orgUnknown
telemetry-incoming.r53-2.services.mozilla.comUnknown
settings-win.data.microsoft.comMicrosoftMicrosoft
gateway-oblivious.apple.comUnknown
calendars.icloud.comUnknown
news-edge.apple.comUnknown
dns.googleUnknown
_dns.resolver.arpaUnknown
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
slscr.update.microsoft.comMicrosoftMicrosoft
fe2cr.update.microsoft.comMicrosoftMicrosoft
download.windowsupdate.comUnknown
geo.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp801.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
au.download.windowsupdate.comUnknown
ecs.office.comUnknown
ocsp.comodoca.com.cdn.cloudflare.netUnknown
lcdn-locator.apple.comUnknown
gsp57-ssl-background.ls.apple.comUnknown
login.live.comUnknown
fe3cr.delivery.mp.microsoft.comMicrosoftMicrosoft
kv501.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp501.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
kv601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
cp601.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
mobile.events.data.microsoft.comMicrosoftMicrosoft
mesu-cdn.origin-apple.com.akadns.netUnknown
stocks-edge.apple.comUnknown
swdist.apple.com.akadns.netUnknown
tas02.sls.update.microsoft.comMicrosoftMicrosoft
xp-cdn-lb.itunes-apple.com.akadns.netUnknown
humb.apple.comUnknown
api.apple-cloudkit.fe2.apple-dns.netUnknown
assets-mercury.mzstatic.comUnknown
cdn.playwright.devUnknown
xp.itunes-apple.com.akadns.netUnknown
c.apple.newsUnknown
swdist.apple.comUnknown
mask.icloud.comUnknown
adl.windows.comUnknown
ipcdn-lb.apple.com.akadns.netUnknown
configuration.apple.com.akadns.netUnknown
swcdn.apple.comUnknown
amp-api.media.apple.comUnknown
help.origin-apple.com.akadns.netUnknown
wns2-by3p.wns.windows.comUnknown
ocsp2.apple.com.edgekey.netUnknown
ipcdn-web.apple.comUnknown
ocsp.usertrust.comUnknown
gsa.apple.comUnknown
gdmf-ados.apple.comUnknown
configuration-lb.ls-apple.com.akadns.netUnknown
client.wns.windows.comUnknown
api.deps.devUnknown
api.osv.devUnknown
api.smoot.apple.comUnknown
api2.smoot.apple.comUnknown
prod.app-api.stepsecurity.ioUnknown
files.pythonhosted.orgPython RegistryPython Registry
optimizationguide-pa.googleapis.comGoogleGoogle
mtalk.google.comUnknown
android.clients.google.comUnknown
semgrep.devUnknown
swdist.g.aaplimg.comUnknown
is3-ssl.mzstatic.comUnknown
is4-ssl.mzstatic.comUnknown
is2-ssl.mzstatic.comUnknown
images-mercury.mzstatic.comUnknown
e3528.dscg.akamaiedge.netUnknown
mail.google.comUnknown
ssl.gstatic.comUnknown
update.googleapis.comGoogleGoogle
edgedl.me.gvt1.comUnknown
fpinit-us-w.edge-itunes-apple.com.akadns.netUnknown
gdmf.v.aaplimg.comUnknown
cp10.cloudflare.comUnknown
clients2.googleusercontent.comUnknown
redirector.gvt1.comUnknown
r1---sn-vgqskns7.gvt1.comUnknown
clients2.google.comUnknown
safebrowsingohttpgateway.googleapis.comGoogleGoogle
accounts.google.comUnknown
www.google.comUnknown
r3---sn-p5qlsny6.gvt1.comUnknown
r5---sn-p5qddn7d.gvt1.comUnknown
r4---sn-najern7k.gvt1.comUnknown
r2---sn-najern7k.gvt1.comUnknown
plugins.jetbrains.comUnknown
downloads.marketplace.jetbrains.comUnknown
xp.v.aaplimg.comUnknown
oneocsp.microsoft.comMicrosoftMicrosoft
www.jetbrains.comUnknown
plugins.gradle.orgGradleGradle
fs.microsoft.comMicrosoftMicrosoft
swscan-cdn.apple.com.akadns.netUnknown
gspe35-ssl.ls.apple.comUnknown
gsp-ssl.ls.apple.comUnknown
gateway.fe2.apple-dns.netUnknown
registry.npmjs.orgnpm Registrynpm Registry
mask-h2.icloud.comUnknown
stocks-data-service.apple.comUnknown
weather-edge.apple.comUnknown
e5977.dsce9.akamaiedge.netUnknown
plugins-artifacts.gradle.orgGradleGradle
displaycatalog.mp.microsoft.comMicrosoftMicrosoft
tas01.cwsapp.update.microsoft.comMicrosoftMicrosoft
tas02.cws.update.microsoft.comMicrosoftMicrosoft
ocsp.edge.digicert.comUnknown
ocsp.comodoca.comUnknown
help.v.aaplimg.comUnknown
compass.mongodb.comUnknown
artifacts-caching-proxy.aws.intellij.netUnknown
cache-redirector.jetbrains.comUnknown
download.jetbrains.comUnknown
download-cdn.jetbrains.comUnknown
d2cico3c979uwg.cloudfront.netUnknown
d2s4y8xcwt8bet.cloudfront.netUnknown
packages.jetbrains.teamUnknown
db2uklzeiyqq6.cloudfront.netUnknown
crl.sectigo.comUnknown
metrics.semgrep.devUnknown
geover.prod.do.dsp.mp.microsoft.comMicrosoftMicrosoft
dl.delivery.mp.microsoft.comMicrosoftMicrosoft
1d.tlu.dl.delivery.mp.microsoft.comMicrosoftMicrosoft
apps-mzstatic-cdn.itunes-apple.com.akadns.netUnknown
r2---sn-p5qs7nd7.gvt1.comUnknown
r4---sn-p5qs7n6y.gvt1.comUnknown
r3---sn-p5qddn7k.gvt1.comUnknown
r2---sn-2op5q5-5n.gvt1.comUnknown
amp-api.media-lb.apple.com.akadns.netUnknown
cdn-h3.g.aaplimg.comUnknown
ohttp-relay1.fastly-edge.comUnknown
itunes.apple.comUnknown
publicassets.cdn-apple.comUnknown
www.googleapis.comGoogleGoogle
voilatile-pa.googleapis.comGoogleGoogle
this-host-cannot-exist.invalidUnknown
rcs-acs-tmo-us.jibe.google.comUnknown
dl.google.comGoogleGoogle
infinitedata-pa.googleapis.comGoogleGoogle
geller-pa.googleapis.comGoogleGoogle
bag-cdn.itunes-apple.com.akadns.netUnknown
tenor.googleapis.comGoogleGoogle
play.googleapis.comGoogleGoogle
gspe1-ssl.ls.apple.comUnknown
r2---sn-p5qlsnrl.gvt1.comUnknown
r4---sn-p5qlsn7d.gvt1.comUnknown
v1.ta2.fe2cr.update.microsoft.comMicrosoftMicrosoft
iadsdk.apple.comUnknown
token.safebrowsing.appleUnknown
is5-ssl.mzstatic.comUnknown
tlu.dl.delivery.mp.microsoft.comMicrosoftMicrosoft
azcliprod.blob.core.windows.netUnknown
dc.services.visualstudio.comUnknown
login.microsoftonline.comMicrosoftMicrosoft
management.azure.comAzureAzure
martincostello.azurecr.ioUnknown
sentry.ioUnknown
de.sentry.ioUnknown
mcr.microsoft.comMicrosoftMicrosoft
fulcio.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
raw.githubusercontent.comGitHubGitHub
tuf-repo-cdn.sigstore.devSigstoreSigstore
westus.data.mcr.microsoft.comMicrosoftMicrosoft
1a.tlu.dl.delivery.mp.microsoft.comMicrosoftMicrosoft
r2---sn-p5qddn7k.gvt1.comUnknown
mesu-cdn.apple.com.akadns.netUnknown
xp.g.aaplimg.comUnknown