StepSecurity Logo
StepSecurity
LoginStart free
docker/login-action

docker/login-action

GitHub Action to login against a Docker registry

GitHubGitHub Repository

1344 stars

Node.js

Node Action

Maintained action available

Score updated 9 hours ago

GitHub Actions security score

docker/login-action

Score

8/10

License

Apache License 2.0

Maintained

15 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

16 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 18736 open-source projects

Security Policy

security policy file detected

Networking Behavior of docker/login-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
index.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
registry-1.docker.ioDockerHubDockerHub
quay.ioUnknown
vprodemo.azurecr.ioUnknown
ghcr.ioGitHubGitHub
registry.gitlab.comGitLabGitLab
gitlab.comGitLabGitLab
api.ecr.eu-west-1.amazonaws.comUnknown
api.ecr-public.us-east-1.amazonaws.comUnknown
public.ecr.awsUnknown
api.github.comGitHubGitHub
production.cloudflare.docker.comDockerHubDockerHub
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
mindarodev.azurecr.ioUnknown
bridgetok8s.azurecr.ioUnknown
us-central1-docker.pkg.devUnknown
iad.mirror.rackspace.comUnknown
mirror.dal.nexril.netUnknown
ziply.mm.fcix.netUnknown
mirrors.fedoraproject.orgUnknown
mirror.23m.comUnknown
mirror-mci.yuki.net.ukUnknown
deb.debian.orgUnknown
mirror.arizona.eduUnknown
mirrors.centos.orgUnknown
mirror.team-cymru.comUnknown
intelaicontainers.azurecr.ioUnknown
dc.services.visualstudio.comUnknown
registry.cn-beijing.aliyuncs.comUnknown
dockerauth.cn-hangzhou.aliyuncs.comUnknown
registry-write.deckhouse.ioUnknown
images.opencadc.orgUnknown
us-west1-docker.pkg.devUnknown
registry.docker.comUnknown
registry.jetbrains.teamUnknown
xpkg.upbound.ioUnknown
quay.nzUnknown
scm.ecodex.euUnknown
api.ecr.us-west-2.amazonaws.comUnknown
080137407410.dkr.ecr.us-west-2.amazonaws.comUnknown
arcbackstage.azurecr.ioUnknown
jenkins.jans.ioUnknown
github.comGitHubGitHub
files.pythonhosted.orgPython RegistryPython Registry
pypi.orgPython RegistryPython Registry
fulcio.sigstore.devSigstoreSigstore
tuf-repo-cdn.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
archive.ubuntu.comUbuntuUbuntu
security.ubuntu.comUbuntuUbuntu
ports.ubuntu.comUbuntuUbuntu
repo1.maven.orgUnknown
maven.jans.ioUnknown
www.apple.comUnknown
mds.fidoalliance.orgUnknown
secure.globalsign.comUnknown
x.cp.wd.microsoft.comMicrosoftMicrosoft
ppa.launchpadcontent.netUnknown
dl.google.comGoogleGoogle
deb.nodesource.comUnknown
dl.k6.ioUnknown
dlcdn.apache.orgUnknown
pkg-containers.githubusercontent.comGitHubGitHub
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
layers.nvcr.ioUnknown
nexus3.o-ran-sc.orgUnknown
cdn01.quay.ioUnknown
mcr.microsoft.comMicrosoftMicrosoft
eastus.data.mcr.microsoft.comMicrosoftMicrosoft
registry.npmjs.orgnpm Registrynpm Registry
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
release-assets.githubusercontent.comGitHubGitHub
raw.githubusercontent.comGitHubGitHub
us-docker.pkg.devUnknown
timestamp.sigstore.devSigstoreSigstore
dhi.ioUnknown