StepSecurity Logo
StepSecurity
LoginStart free
sigstore/cosign-installer

sigstore/cosign-installer

Cosign Github Action

GitHubGitHub Repository

191 stars

Composite

Maintained action available

Score updated 2 days ago

GitHub Actions security score

sigstore/cosign-installer

Score

8/10

License

Apache License 2.0

Maintained

10 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 9

Vulnerabilities

0 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 5232 open-source projects

Security Policy

security policy file detected

Networking Behavior of sigstore/cosign-installer

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
github.comGitHubGitHub
objects.githubusercontent.comGitHubGitHub
raw.githubusercontent.comGitHubGitHub
tuf-repo-cdn.sigstore.devSigstoreSigstore
storage.googleapis.comGoogleGoogle
keyserver.ubuntu.comUbuntuUbuntu
deb.debian.orgUnknown
iad.mirror.rackspace.comUnknown
ghcr.ioGitHubGitHub
mirrors.centos.orgUnknown
ziply.mm.fcix.netUnknown
cdn03.quay.ioUnknown
ftp-osl.osuosl.orgUnknown
pkg-containers.githubusercontent.comGitHubGitHub
mirror.pilotfiber.comUnknown
mirror.team-cymru.comUnknown
na.edge.kernel.orgUnknown
pubmirror1.math.uh.eduUnknown
mirror.scaleuptech.comUnknown
mirrors.wcupa.eduUnknown
epel.mirror.constant.comUnknown
repo.ialab.dsu.eduUnknown
mirror.rackspace.comUnknown
rekor.sigstore.devSigstoreSigstore
release-assets.githubusercontent.comGitHubGitHub
global.endpoint.security.microsoft.comMicrosoftMicrosoft
proxy.golang.orgGolang ProxyGolang Proxy
sum.golang.orgUnknown
us-docker.pkg.devUnknown
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
releases.hashicorp.comHashiCorpHashiCorp
checkpoint-api.hashicorp.comUnknown
check.trivy.devUnknown
api.github.comGitHubGitHub
registry-1.docker.ioDockerHubDockerHub
x.cp.wd.microsoft.comMicrosoftMicrosoft
schema.blue-build.orgUnknown
negativo17.orgUnknown
mirrors.fedoraproject.orgUnknown
download.copr.fedorainfracloud.orgUnknown
pkgs.tailscale.comUnknown
nnenix.mm.fcix.netUnknown
fedoraproject-updates-archive.fedoraproject.orgUnknown
nvidia.github.ioUnknown
coresite-atl.mm.fcix.netUnknown
mirror.web-ster.comUnknown
mirror.chpc.utah.eduUnknown
cofractal-sea.mm.fcix.netUnknown
mirror.fcix.netUnknown
gigsouth.mm.fcix.netUnknown
ftp-chi.osuosl.orgUnknown
paducahix.mm.fcix.netUnknown
download-ib01.fedoraproject.orgUnknown
opencolo.mm.fcix.netUnknown
pubmirror2.math.uh.eduUnknown
solidrock.mm.fcix.netUnknown
lolhost.mm.fcix.netUnknown
mirror.lstn.netUnknown
volico.mm.fcix.netUnknown
get.anchore.ioUnknown
ocsp.comodoca.comUnknown
ocsp.usertrust.comUnknown
dns.msftncsi.comUnknown
x1.c.lencr.orgUnknown
r12.c.lencr.orgUnknown
client.wns.windows.comUnknown
configuration.apple.comUnknown
fe2cr.update.microsoft.comMicrosoftMicrosoft
packages.microsoft.comMicrosoftMicrosoft
index.docker.ioDockerHubDockerHub
fulcio.sigstore.devSigstoreSigstore
timestamp.sigstore.devSigstoreSigstore
swscan.apple.comUnknown
swdist.apple.comUnknown