StepSecurity Logo
StepSecurity
LoginStart free
svenstaro/upload-release-action

svenstaro/upload-release-action

Upload files to a GitHub release

GitHubGitHub Repository

710 stars

Node.js

Node Action

Maintained action available

Score updated 5 days ago

GitHub Actions security score

svenstaro/upload-release-action

Score

4/10

License

MIT License

Maintained

5 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 5

Vulnerabilities

14 existing vulnerabilities detected

Branch protection

branch protection not enabled on development/release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 5240 open-source projects

Security Policy

security policy file not detected

Networking Behavior of svenstaro/upload-release-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
api.github.comGitHubGitHub
uploads.github.comGitHubGitHub
gdmf.apple.comUnknown
bag.itunes.apple.comUnknown
experiments.apple.comUnknown
configuration.apple.comUnknown
humb.apple.comUnknown
xp-cdn-lb.itunes-apple.com.akadns.netUnknown
calendars.icloud.comUnknown
swscan.apple.comUnknown
swdist.apple.comUnknown
fbs.smoot.apple.comUnknown
xp.apple.comUnknown
help.apple.comUnknown
ipcdn.apple.comUnknown
apple-relay.cloudflare.comUnknown
ocsp2.apple.comUnknown
s.mzstatic.comUnknown
fpinit.itunes.apple.comUnknown
sf-api-token-service.itunes.apple.comUnknown
cdn-h3.g.aaplimg.comUnknown