sigstore/cosign-installer
Cosign Github Action
GitHub Actions security score
| sigstore/cosign-installer | |
|---|---|
Score | 8/10 |
License | Apache License 2.0 |
Maintained | 10 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 9 |
Vulnerabilities | 0 existing vulnerabilities detected |
Branch protection | branch protection is not maximal on development and all release branches |
Manual code review | - |
Secure publishing | - |
Signed commits | - |
Automated security tools | - |
Popular | Used by 5232 open-source projects |
Security Policy | security policy file detected |
Networking Behavior of sigstore/cosign-installer
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
Popular DestinationUnknown Destination
| Network Destination | Owner |
|---|---|
| github.com | |
| objects.githubusercontent.com | |
| raw.githubusercontent.com | |
| tuf-repo-cdn.sigstore.dev | |
| storage.googleapis.com | |
| keyserver.ubuntu.com | |
| deb.debian.org | Unknown |
| iad.mirror.rackspace.com | Unknown |
| ghcr.io | |
| mirrors.centos.org | Unknown |
| ziply.mm.fcix.net | Unknown |
| cdn03.quay.io | Unknown |
| ftp-osl.osuosl.org | Unknown |
| pkg-containers.githubusercontent.com | |
| mirror.pilotfiber.com | Unknown |
| mirror.team-cymru.com | Unknown |
| na.edge.kernel.org | Unknown |
| pubmirror1.math.uh.edu | Unknown |
| mirror.scaleuptech.com | Unknown |
| mirrors.wcupa.edu | Unknown |
| epel.mirror.constant.com | Unknown |
| repo.ialab.dsu.edu | Unknown |
| mirror.rackspace.com | Unknown |
| rekor.sigstore.dev | |
| release-assets.githubusercontent.com | |
| global.endpoint.security.microsoft.com | |
| proxy.golang.org | |
| sum.golang.org | Unknown |
| us-docker.pkg.dev | Unknown |
| dl-cdn.alpinelinux.org | |
| auth.docker.io | |
| production.cloudflare.docker.com | |
| releases.hashicorp.com | |
| checkpoint-api.hashicorp.com | Unknown |
| check.trivy.dev | Unknown |
| api.github.com | |
| registry-1.docker.io | |
| x.cp.wd.microsoft.com | |
| schema.blue-build.org | Unknown |
| negativo17.org | Unknown |
| mirrors.fedoraproject.org | Unknown |
| download.copr.fedorainfracloud.org | Unknown |
| pkgs.tailscale.com | Unknown |
| nnenix.mm.fcix.net | Unknown |
| fedoraproject-updates-archive.fedoraproject.org | Unknown |
| nvidia.github.io | Unknown |
| coresite-atl.mm.fcix.net | Unknown |
| mirror.web-ster.com | Unknown |
| mirror.chpc.utah.edu | Unknown |
| cofractal-sea.mm.fcix.net | Unknown |
| mirror.fcix.net | Unknown |
| gigsouth.mm.fcix.net | Unknown |
| ftp-chi.osuosl.org | Unknown |
| paducahix.mm.fcix.net | Unknown |
| download-ib01.fedoraproject.org | Unknown |
| opencolo.mm.fcix.net | Unknown |
| pubmirror2.math.uh.edu | Unknown |
| solidrock.mm.fcix.net | Unknown |
| lolhost.mm.fcix.net | Unknown |
| mirror.lstn.net | Unknown |
| volico.mm.fcix.net | Unknown |
| get.anchore.io | Unknown |
| ocsp.comodoca.com | Unknown |
| ocsp.usertrust.com | Unknown |
| dns.msftncsi.com | Unknown |
| x1.c.lencr.org | Unknown |
| r12.c.lencr.org | Unknown |
| client.wns.windows.com | Unknown |
| configuration.apple.com | Unknown |
| fe2cr.update.microsoft.com | |
| packages.microsoft.com | |
| index.docker.io | |
| fulcio.sigstore.dev | |
| timestamp.sigstore.dev | |
| swscan.apple.com | Unknown |
| swdist.apple.com | Unknown |