step-security/docker-build-push-action

step-security/docker-build-push-action

GitHub Action to build and push Docker images with Buildx.

GitHubGitHub Repository

0 stars

Node.js

Node Action

Maintained by StepSecurity

Score updated 3 days ago

GitHub Actions security score comparison

step-security/docker-build-push-actiondocker/build-push-action

Score

10/10

8/10

License

Apache License 2.0Apache License 2.0

Maintained

Maintained by StepSecurity30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10

Vulnerabilities

2 existing vulnerabilities detected

16 existing vulnerabilities detected

Branch protection

Branch protection is maximal on development and all release branches

branch protection is not maximal on development and all release branches

Manual code review

Upstream changes are reviewed before merging-

Secure publishing

Reproducible builds with SBOM and provenance-

Signed commits

All commits are signed-

Automated security tools

Findings from tools are triaged and fixed before each change-

Popular

Used by StepSecurity enterprise customersUsed by 35696 open-source projects

Security Policy

security policy file detectedsecurity policy file detected

Networking Behavior of step-security/docker-build-push-action

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
registry-1.docker.ioDockerHubDockerHub
auth.docker.ioDockerHubDockerHub
production.cloudflare.docker.comDockerHubDockerHub
ghcr.ioGitHubGitHub
gcr.ioUnknown
static.rust-lang.orgUnknown
index.crates.ioUnknown
static.crates.ioUnknown
debian.map.fastlydns.netUnknown
_http._tcp.deb.debian.orgUnknown
registry.npmjs.orgnpm Registrynpm Registry
pkg-containers.githubusercontent.comGitHubGitHub
security.ubuntu.comUbuntuUbuntu
archive.ubuntu.comUbuntuUbuntu
ports.ubuntu.comUbuntuUbuntu
_http._tcp.archive.ubuntu.comUbuntuUbuntu
_http._tcp.security.ubuntu.comUbuntuUbuntu
_http._tcp.ports.ubuntu.comUbuntuUbuntu
github.comGitHubGitHub
release-assets.githubusercontent.comGitHubGitHub
files.pythonhosted.orgPython RegistryPython Registry
deb.debian.orgUnknown
dl-cdn.alpinelinux.orgAlpine LinuxAlpine Linux
caddyserver.comUnknown
registry.yarnpkg.comUnknown
sdk.cloud.google.comUnknown
dl.google.comGoogleGoogle
mcr.microsoft.comMicrosoftMicrosoft
centralus.data.mcr.microsoft.comMicrosoftMicrosoft
dc.services.visualstudio.comUnknown
api.nuget.orgUnknown
crl3.digicert.comUnknown
ts-crl.ws.symantec.comUnknown
s.symcb.comUnknown
crl4.digicert.comUnknown
eastus.data.mcr.microsoft.comMicrosoftMicrosoft
proxy.golang.orgGolang ProxyGolang Proxy
sum.golang.orgUnknown
storage.googleapis.comGoogleGoogle
releases.astral.shUnknown
westus.data.mcr.microsoft.comMicrosoftMicrosoft
deb.nodesource.comUnknown
westus2.data.mcr.microsoft.comMicrosoftMicrosoft