StepSecurity Logo
StepSecurity
LoginStart free
docker/metadata-action

docker/metadata-action

GitHub Action to extract metadata (tags, labels) from Git reference and GitHub events for Docker

GitHubGitHub Repository

1130 stars

Node.js

Node Action

Maintained action available

Score updated 12 hours ago

GitHub Actions security score

docker/metadata-action

Score

8/10

License

Apache License 2.0

Maintained

30 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

16 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 29568 open-source projects

Security Policy

security policy file detected

Networking Behavior of docker/metadata-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
registry.uffizzi.comUnknown
mirror1.hs-esslingen.deUnknown
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
centos-stream-distro.1gservers.comUnknown
keyserver.ubuntu.comUbuntuUbuntu
github.comGitHubGitHub
security.ubuntu.comUbuntuUbuntu
archive.ubuntu.comUbuntuUbuntu
pypi.orgPython RegistryPython Registry
files.pythonhosted.orgPython RegistryPython Registry
developer.arm.comUnknown
armkeil.blob.core.windows.netUnknown
x.cp.wd.microsoft.comMicrosoftMicrosoft
global.endpoint.security.microsoft.comMicrosoftMicrosoft
wdcp.microsoft.comMicrosoftMicrosoft
go.microsoft.comMicrosoftMicrosoft
definitionupdates.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
westus2.data.mcr.microsoft.comMicrosoftMicrosoft
westus.data.mcr.microsoft.comMicrosoftMicrosoft
mcr.microsoft.comMicrosoftMicrosoft
ghcr.ioGitHubGitHub
pkg-containers.githubusercontent.comGitHubGitHub
release-assets.githubusercontent.comGitHubGitHub
download.pytorch.orgUnknown
settings-win.data.microsoft.comMicrosoftMicrosoft
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
prod.app-api.stepsecurity.ioUnknown
www.openssl.orgUnknown
mirror.gcr.ioUnknown
check.trivy.devUnknown
deb.debian.orgUnknown
index.crates.ioUnknown
static.crates.ioUnknown
tuf-repo-cdn.sigstore.devSigstoreSigstore
fulcio.sigstore.devSigstoreSigstore
timestamp.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
cafe.github.comGitHubGitHub
production.cloudfront.docker.comUnknown
ports.ubuntu.comUbuntuUbuntu
dc.services.visualstudio.comUnknown
api.nuget.orgUnknown
crl3.digicert.comUnknown
www.microsoft.comMicrosoftMicrosoft
crl.sectigo.comUnknown
eastus.data.mcr.microsoft.comMicrosoftMicrosoft
ts-crl.ws.symantec.comUnknown
s.symcb.comUnknown
crl4.digicert.comUnknown
crl.usertrust.comUnknown
dns.msftncsi.comUnknown
get.trivy.devUnknown