devcontainers/ci
A GitHub Action and Azure DevOps Task designed to simplify using Dev Containers (https://containers.dev) in CI/CD systems.
GitHub Actions security score
| devcontainers/ci | |
|---|---|
Score | 7/10 |
License | MIT License |
Maintained | 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10 |
Vulnerabilities | 16 existing vulnerabilities detected |
Branch protection | Branch protection is maximal on development and all release branches |
Manual code review | - |
Secure publishing | - |
Signed commits | - |
Automated security tools | - |
Popular | Used by 1228 open-source projects |
Security Policy | security policy file not detected |
Networking Behavior of devcontainers/ci
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
Popular DestinationUnknown Destination
| Network Destination | Owner |
|---|---|
| registry.npmjs.org | |
| containers.dev | Unknown |
| centralus.data.mcr.microsoft.com | |
| ghcr.io | |
| pkg-containers.githubusercontent.com | |
| registry-1.docker.io | |
| auth.docker.io | |
| production.cloudflare.docker.com | |
| pypi.org | |
| files.pythonhosted.org | |
| deb.debian.org | Unknown |
| dl.yarnpkg.com | Unknown |
| github.com | |
| objects.githubusercontent.com | |
| webi.sh | Unknown |
| apt.releases.hashicorp.com | Unknown |
| mcr.microsoft.com | |
| eastus.data.mcr.microsoft.com | |
| packages.microsoft.com | |
| go.googlesource.com | Unknown |
| dl.google.com | |
| golang.org | Unknown |
| go.dev | Unknown |
| proxy.golang.org | |
| sum.golang.org | Unknown |
| raw.githubusercontent.com | |
| dl.k8s.io | Unknown |
| cdn.dl.k8s.io | Unknown |
| get.helm.sh | Unknown |
| storage.googleapis.com | |
| releases.hashicorp.com | |
| keyserver.ubuntu.com | |
| tuf-repo-cdn.sigstore.dev | |
| rekor.sigstore.dev | |
| api.github.com | |
| www.postgresql.org | Unknown |
| apt.postgresql.org | Unknown |
| westus.data.mcr.microsoft.com | |
| westus2.data.mcr.microsoft.com | |
| o4504983808901120.ingest.sentry.io | Unknown |
| keyserver.pgp.com | Unknown |
| keys.openpgp.org | Unknown |
| debian.map.fastlydns.net | Unknown |
| api.adoptium.net | Unknown |
| api.sdkman.io | Unknown |
| dlcdn.apache.org | Unknown |
| nodejs.org | Unknown |
| plantuml.com | Unknown |
| www.plantuml.com | Unknown |
| westcentralus.data.mcr.microsoft.com | |
| index.rubygems.org | |
| mcrprod.azurecr.io | Unknown |
| release-assets.githubusercontent.com | |
| docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.com | |
| download.docker.com | Unknown |
| kind.sigs.k8s.io | Unknown |
| go.kubebuilder.io | Unknown |
| gcr.io | Unknown |
| prod.app-api.stepsecurity.io | Unknown |
| binaries.sonarsource.com | Unknown |
| galaxy.ansible.com | Unknown |
| ansible-galaxy-ng.s3.dualstack.us-east-1.amazonaws.com | Unknown |
| get.sdkman.io | Unknown |
| broker.sdkman.io | Unknown |
| aka.ms | Unknown |
| download.visualstudio.microsoft.com | |
| iojs.org | Unknown |
| downloads.snyk.io | Unknown |
| api.snyk.io | Unknown |
| get.chezmoi.io | Unknown |
| formulae.brew.sh | Unknown |
| eu-central-1-1.aws.cloud2.influxdata.com | Unknown |
| www.powershellgallery.com | Unknown |
| cdn.powershellgallery.com | Unknown |
| mise.run | Unknown |
| mise.en.dev | Unknown |
| mise-versions.jdx.dev | Unknown |
| archive.ubuntu.com | |
| deb.gierens.de | Unknown |
| starship.rs | Unknown |
| security.ubuntu.com | |
| cli.github.com | |
| repo.yarnpkg.com | Unknown |
| registry.yarnpkg.com | Unknown |
| dc.services.visualstudio.com | Unknown |