StepSecurity Logo
StepSecurity
LoginStart free
goreleaser/goreleaser-action

goreleaser/goreleaser-action

GitHub Action for GoReleaser

GitHubGitHub Repository

1012 stars

Node.js

Node Action

Maintained action available

Score updated 10 hours ago

GitHub Actions security score

goreleaser/goreleaser-action

Score

7/10

License

MIT License

Maintained

21 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

19 existing vulnerabilities detected

Branch protection

Branch protection is maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 7524 open-source projects

Security Policy

security policy file not detected

Networking Behavior of goreleaser/goreleaser-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
goreleaser.comUnknown
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
api.github.comGitHubGitHub
uploads.github.comGitHubGitHub
api.gumroad.comUnknown
cgr.devUnknown
ghcr.ioGitHubGitHub
9236a389bd48b984df91adc1bc924620.r2.cloudflarestorage.comUnknown
pkg-containers.githubusercontent.comGitHubGitHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
registry-1.docker.ioDockerHubDockerHub
proxy.golang.orgGolang ProxyGolang Proxy
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
security.ubuntu.comUbuntuUbuntu
archive.ubuntu.comUbuntuUbuntu
toolbox-data.anchore.ioUnknown
fulcio.sigstore.devSigstoreSigstore
tuf-repo-cdn.sigstore.devSigstoreSigstore
rekor.sigstore.devSigstoreSigstore
gcr.ioUnknown
storage.googleapis.comGoogleGoogle
golang.orgUnknown
raw.githubusercontent.comGitHubGitHub
sum.golang.orgUnknown
deb.debian.orgUnknown
index.crates.ioUnknown
static.crates.ioUnknown
itunesconnect.apple.comUnknown
go.opentelemetry.ioUnknown
sigs.k8s.ioUnknown
k8s.ioUnknown
go.step.smUnknown
filippo.ioUnknown
gopkg.inUnknown
gitlab.alpinelinux.orgUnknown
cloud.google.comUnknown
google.golang.orgUnknown
go.mongodb.orgUnknown
cuelang.orgUnknown
dario.catUnknown
go.uber.orgUnknown
go.opencensus.ioUnknown
modernc.orgUnknown
registry.npmjs.orgnpm Registrynpm Registry
api.bitbucket.orgUnknown
cuelabs.devUnknown
go.devUnknown
dl.google.comGoogleGoogle
timestamp.apple.comUnknown
appstoreconnect.apple.comUnknown
notary-submissions-prod.s3.us-west-2.amazonaws.comUnknown
notary-artifacts-prod.s3.amazonaws.comUnknown
github-cloud.githubusercontent.comGitHubGitHub
oauth2.sigstore.devSigstoreSigstore
gomodules.xyzUnknown
mxpiie2aqamhhtr7w4yfawze.blob.core.windows.netUnknown
4jf3cduo6vaxhyvmpcxho6q4.blob.core.windows.netUnknown
index.docker.ioDockerHubDockerHub
cel.devUnknown
6unwx7trmgfpg6jtrbo6xyez.blob.core.windows.netUnknown
docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.comDockerHubDockerHub
kzswwwxcwjsi32dxsjoa5jpm.blob.core.windows.netUnknown
amqmxcukf4nx2hxnti3qasgi.blob.core.windows.netUnknown
sooghdm3f6ucqse4spiu5z3x.blob.core.windows.netUnknown
qoskr3il3m32lirofaabrd4m.blob.core.windows.netUnknown
gitlab.comGitLabGitLab
aur.archlinux.orgUnknown
cue.devUnknown
release-assets.githubusercontent.comGitHubGitHub
static.rust-lang.orgUnknown
aka.msUnknown
download.visualstudio.microsoft.comMicrosoftMicrosoft
azure.archive.ubuntu.comUbuntuUbuntu
go.yaml.inUnknown
us-v20.events.data.microsoft.comMicrosoftMicrosoft
winatp-gw-cus.microsoft.comMicrosoftMicrosoft
unitedstates.x.cp.wd.microsoft.comMicrosoftMicrosoft
timestamp.sigstore.devSigstoreSigstore
api.pulumi.comUnknown
registry.opentofu.orgUnknown
wsraa2odpfgvtjrjqqmv4qg4.blob.core.windows.netUnknown
vesqzr2vt5fb2gqexdvyotti.blob.core.windows.netUnknown
jul2twlwang73bcn3z6jbtle.blob.core.windows.netUnknown
v46wwfyathtbwbr6pf7bedj3.blob.core.windows.netUnknown
c2wdlpa46mmh72d7jcvwfvrf.blob.core.windows.netUnknown
g4uhjfqoa6j23os7nreac5af.blob.core.windows.netUnknown
c4ls2ojmf5z5v2m23ehr4asi.blob.core.windows.netUnknown
xr4hwddoz7nzti7pqph2fppt.blob.core.windows.netUnknown
ckfyrwywtexoqc4pbug7y34y.blob.core.windows.netUnknown
7o6jxbetjfdcy7e5kypq6wm4.blob.core.windows.netUnknown
64hycvbg6vghr4ztqshj25uc.blob.core.windows.netUnknown
bnpkr7qn4r37ff43s5qulbh4.blob.core.windows.netUnknown
x4z27oip6c7uuatddr5crxmv.blob.core.windows.netUnknown
rihggasr56wjzjnvo4wfgckp.blob.core.windows.netUnknown
packages.microsoft.comMicrosoftMicrosoft
o4511127271636992.ingest.us.sentry.ioUnknown
europe-docker.pkg.devUnknown
iamcredentials.googleapis.comGoogleGoogle
sts.googleapis.comGoogleGoogle
prod.app-api.stepsecurity.ioUnknown
push.fury.ioUnknown
apk.cgr.devUnknown
production.cloudfront.docker.comUnknown
cloudkms.googleapis.comGoogleGoogle
secure.globalsign.comUnknown
timestamp.digicert.comUnknown
containerbutler-bxene7duhhe5d8cy.azurecr.ioUnknown
us-central1-docker.pkg.devUnknown
227747745188.dkr.ecr.us-east-1.amazonaws.comUnknown
example.comUnknown
httpbin.orgUnknown
registry.terraform.ioUnknown
kgzophhkddivmdt7ompktjoj.blob.core.windows.netUnknown
udp.usage.shopware.ioUnknown
upload.cloudsmith.ioUnknown
api.cloudsmith.ioUnknown
cafe.github.comGitHubGitHub
709825985650.dkr.ecr.us-east-1.amazonaws.comUnknown
testa.azurecr.ioUnknown
containerbutler.azurecr.ioUnknown
us-docker.pkg.devUnknown
packages.wolfi.devUnknown