StepSecurity Logo
StepSecurity
LoginStart free
devcontainers/ci

devcontainers/ci

A GitHub Action and Azure DevOps Task designed to simplify using Dev Containers (https://containers.dev) in CI/CD systems.

GitHubGitHub Repository

478 stars

Node.js

Node Action

Maintained action available

Score updated 5 days ago

GitHub Actions security score

devcontainers/ci

Score

7/10

License

MIT License

Maintained

30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

16 existing vulnerabilities detected

Branch protection

Branch protection is maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 1228 open-source projects

Security Policy

security policy file not detected

Networking Behavior of devcontainers/ci

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
registry.npmjs.orgnpm Registrynpm Registry
containers.devUnknown
centralus.data.mcr.microsoft.comMicrosoftMicrosoft
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
deb.debian.orgUnknown
dl.yarnpkg.comUnknown
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
webi.shUnknown
apt.releases.hashicorp.comUnknown
mcr.microsoft.comMicrosoftMicrosoft
eastus.data.mcr.microsoft.comMicrosoftMicrosoft
packages.microsoft.comMicrosoftMicrosoft
go.googlesource.comUnknown
dl.google.comGoogleGoogle
golang.orgUnknown
go.devUnknown
proxy.golang.orgGolang ProxyGolang Proxy
sum.golang.orgUnknown
raw.githubusercontent.comGitHubGitHub
dl.k8s.ioUnknown
cdn.dl.k8s.ioUnknown
get.helm.shUnknown
storage.googleapis.comGoogleGoogle
releases.hashicorp.comHashiCorpHashiCorp
keyserver.ubuntu.comUbuntuUbuntu
tuf-repo-cdn.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
api.github.comGitHubGitHub
www.postgresql.orgUnknown
apt.postgresql.orgUnknown
westus.data.mcr.microsoft.comMicrosoftMicrosoft
westus2.data.mcr.microsoft.comMicrosoftMicrosoft
o4504983808901120.ingest.sentry.ioUnknown
keyserver.pgp.comUnknown
keys.openpgp.orgUnknown
debian.map.fastlydns.netUnknown
api.adoptium.netUnknown
api.sdkman.ioUnknown
dlcdn.apache.orgUnknown
nodejs.orgUnknown
plantuml.comUnknown
www.plantuml.comUnknown
westcentralus.data.mcr.microsoft.comMicrosoftMicrosoft
index.rubygems.orgRubyGemsRubyGems
mcrprod.azurecr.ioUnknown
release-assets.githubusercontent.comGitHubGitHub
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
download.docker.comUnknown
kind.sigs.k8s.ioUnknown
go.kubebuilder.ioUnknown
gcr.ioUnknown
prod.app-api.stepsecurity.ioUnknown
binaries.sonarsource.comUnknown
galaxy.ansible.comUnknown
ansible-galaxy-ng.s3.dualstack.us-east-1.amazonaws.comUnknown
get.sdkman.ioUnknown
broker.sdkman.ioUnknown
aka.msUnknown
download.visualstudio.microsoft.comMicrosoftMicrosoft
iojs.orgUnknown
downloads.snyk.ioUnknown
api.snyk.ioUnknown
get.chezmoi.ioUnknown
formulae.brew.shUnknown
eu-central-1-1.aws.cloud2.influxdata.comUnknown
www.powershellgallery.comUnknown
cdn.powershellgallery.comUnknown
mise.runUnknown
mise.en.devUnknown
mise-versions.jdx.devUnknown
archive.ubuntu.comUbuntuUbuntu
deb.gierens.deUnknown
starship.rsUnknown
security.ubuntu.comUbuntuUbuntu
cli.github.comGitHubGitHub
repo.yarnpkg.comUnknown
registry.yarnpkg.comUnknown
dc.services.visualstudio.comUnknown