step-security/setup-scala
Secure drop-in replacement for olafurpg/setup-scala
GitHub Action to install any version of Java (GraalVM, Java 8, Java 11, Java 14, ...) via Jabba. Works for any JVM language including Java, Scala and Kotlin.
GitHub Actions security score comparison
| step-security/setup-scala | olafurpg/setup-scala | |
|---|---|---|
Score | 10/10 | 3/10 |
Pinnable | Yes | Yes |
License | MIT License | MIT License |
Maintained | Maintained by StepSecurity | 0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0 |
Vulnerabilities | 2 existing vulnerabilities detected | 43 existing vulnerabilities detected |
Branch protection | Branch protection is maximal on development and all release branches | branch protection not enabled on development/release branches |
AI analysis | Not analyzed yet | Not analyzed yet |
Manual code review | Upstream changes are reviewed before merging | - |
Secure publishing | Reproducible builds with SBOM and provenance | - |
Signed commits | All commits are signed | - |
Automated security tools | Findings from tools are triaged and fixed before each change | - |
Popular | Used by StepSecurity enterprise customers | Used by 1572 open-source projects |
Security Policy | security policy file detected | security policy file not detected |
Networking Behavior of step-security/setup-scala
This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.
| Network Destination | Owner |
|---|---|
| github.com | |
| release-assets.githubusercontent.com | |
| raw.githubusercontent.com |