StepSecurity Logo
actions/checkout

actions/checkout

Action for checking out a repo

GitHubGithub Repository

6025 stars

Node.js

Node Action

Updated 6 days ago

GitHub Actions security score

actions/checkout

Score

9/10

License

MIT License

Maintained

9 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 8

Vulnerabilities

2 existing vulnerabilities detected

Branch protection

branch protection is not maximal on development and all release branches

Manual code review

-

Secure publishing

-

Signed commits

-

Automated security tools

-

Popular

Used by 1027072 open-source projects

Security Policy

security policy file detected

Networking Behavior of actions/checkout

This GitHub Action often makes outbound network calls to these destinations, as gathered from public workflows using the Harden-Runner GitHub Action. Harden-Runner offers network egress filtering and runtime security for both GitHub-hosted and self-hosted runners.

Popular DestinationUnknown Destination
Network DestinationOwner
github.comGitHubGitHub
skia.googlesource.comUnknown
[GitHub Cache Endpoint]Unknown
gcr.ioUnknown
boringssl.googlesource.comUnknown
r8.googlesource.comUnknown
git.kernel.dkUnknown
api.github.comGitHubGitHub
Unknown
motd.ubuntu.comUbuntuUbuntu
fake15.comUnknown
fake16.comUnknown
github-cloud.githubusercontent.comGitHubGitHub
fake11.comUnknown
fake12.comUnknown
yum.oracle.comUnknown
mirrors.vcea.wsu.eduUnknown
d2lzkl7pfhq30w.cloudfront.netUnknown
mirrors.wcupa.eduUnknown
atl.mirrors.knownhost.comUnknown
chromium.googlesource.comUnknown
cdn.fwupd.orgUnknown
provjobdsettingscdn.blob.core.windows.netUnknown
patch-diff.githubusercontent.comGitHubGitHub
instrumentation-telemetry-intake.datadoghq.comUnknown
powitni3dvag4e3vfsuxwbdl.blob.core.windows.netUnknown
auth.safetycli.comUnknown
api.securityscorecards.devUnknown
scans-in.gradle.comUnknown
repos.eggycrew.comUnknown
ftp-nyc.osuosl.orgUnknown
mirror.umd.eduUnknown
nnenix.mm.fcix.netUnknown
ix-denver.mm.fcix.netUnknown
dc.services.visualstudio.comUnknown
sum.golang.orgUnknown
ipfs-adebp.gke-europe.settlemint.comUnknown
objects-origin.githubusercontent.comGitHubGitHub
ipfs-ws.neaweb.chUnknown
md-hdd-x34t55m1pqzm.z23.blob.storage.azure.netUnknown
ipfs-swarm.greyh.atUnknown
md-hdd-ch0jrglqk0w2.z11.blob.storage.azure.netUnknown
md-hdd-jj2w313nlcgg.z19.blob.storage.azure.netUnknown
md-hdd-vd2pqrzzvvv5.z20.blob.storage.azure.netUnknown
md-hdd-zf2t32fvnrxk.z44.blob.storage.azure.netUnknown
md-hdd-ncs2v2spkcl4.z37.blob.storage.azure.netUnknown
md-hdd-r4vqq22sdkjm.z9.blob.storage.azure.netUnknown
md-hdd-qhrbrgldgfkb.z16.blob.storage.azure.netUnknown
md-hdd-hfjm12dp4qlt.z27.blob.storage.azure.netUnknown
md-hdd-f1c2wpzxk3fq.z30.blob.storage.azure.netUnknown
md-hdd-ghczzc132dqm.z13.blob.storage.azure.netUnknown
md-hdd-qg4fsnjtspmb.z13.blob.storage.azure.netUnknown
md-hdd-smw0kvh5fzxx.z29.blob.storage.azure.netUnknown
md-hdd-ngxvfwl1mzjk.z11.blob.storage.azure.netUnknown
md-hdd-gt53vrh2c1pj.z13.blob.storage.azure.netUnknown
md-hdd-kzt1j2js5tc1.z48.blob.storage.azure.netUnknown
md-hdd-21bckzxrz2bh.z5.blob.storage.azure.netUnknown
home.pathin.meUnknown
openthread.ioUnknown
ipfs.axlabs.netUnknown
checkpoint-cn.yeaosound.comUnknown
telemetry.redwoodjs.comUnknown
srv.nullob.siUnknown
md-hdd-zjclzszfctwn.z24.blob.storage.azure.netUnknown
md-hdd-rjdcznvlvq1g.z22.blob.storage.azure.netUnknown
md-hdd-km3lbp0pqwfp.z41.blob.storage.azure.netUnknown
config.datadoghq.comUnknown
ipfs-node.pcdn.svconcloud.comUnknown
ipfs-c9a6p.settlemint.comUnknown
github.com.kktgveqfb1qudcmjlb3z23h2tb.xx.internal.cloudapp.netUnknown
dweb.quartzbear.linkUnknown
md-hdd-xwknwfkphbzw.z37.blob.storage.azure.netUnknown
am6.bootstrap.libp2p.ioUnknown
md-hdd-m32mmw32twwl.z20.blob.storage.azure.netUnknown
md-hdd-pvptbh2bvmhk.z22.blob.storage.azure.netUnknown
md-hdd-2l3d1npbbktj.z3.blob.storage.azure.netUnknown
ipfs-store-48eep.settlemint.comUnknown
home.xupernode.comUnknown
ipfs-store-3d9ep.settlemint.comUnknown
sv16.bootstrap.libp2p.ioUnknown
sg1.bootstrap.libp2p.ioUnknown
ipfs1-8c58p.aks-middleeast.settlemint.comUnknown
microsoft.comMicrosoftMicrosoft
packages.microsoft.comMicrosoftMicrosoft
va1.bootstrap.libp2p.ioUnknown
se1.files.someguy123.comUnknown
ipfs-92a0p.settlemint.comUnknown
qrze66qtsvxvfqere2mfdeot.blob.core.windows.netUnknown
aab76adad815848ca82122392d46393c-1873381457.us-east-2.elb.amazonaws.comUnknown
gitlab.comGitLabGitLab
2dg2rikggido7fysjhd7mr5c.blob.core.windows.netUnknown
t2g5a7hsasfeeerv7pdgpygo.blob.core.windows.netUnknown
istanbul.le-space.deUnknown
sony-bank-development-ipfs-1-36dfp.gke-japan.settlemint.comUnknown
checkpoint-hk.ipns.networkUnknown
checkpoint-hk.yeaosound.comUnknown
a2a4c5c095f8f4421ae16786a4865406-692485639.us-east-2.elb.amazonaws.comUnknown
repo.maven.apache.orgUnknown
api.ipify.orgUnknown
containers.pkg.github.comGitHubGitHub
datapod-ws.gdev.1000i100.frUnknown
gdev.1000i100.frUnknown
s3zwo47y6v6ynwdzeq42glrv.blob.core.windows.netUnknown
greenbond.esUnknown
ipfs-store-cfc9p.settlemint.comUnknown
nft-ipfs-d9e4p.settlemint.comUnknown
ipfs-a84aap.gke-europe-staging.settlemint.comUnknown
atd-ipfs-1-62d0cp.gke-europe.settlemint.comUnknown
ipfs.22336699.xyzUnknown
ipfs-1-212eep.gke-europe-staging.settlemint.comUnknown
threadgroup.orgUnknown
link.springer.comUnknown
ipns-kubo-2.vin1.filebase.ioUnknown
pmu-skat-ipfs-7541cp.gke-europe-staging.settlemint.comUnknown
p2p.gke-middleeast.settlemint.comUnknown
objects.githubusercontent.comGitHubGitHub