ActionRank

HashiCorp Vault

Actively maintained

hashicorp/vault-action · MIT

A GitHub Action that simplifies using HashiCorp Vault™ secrets as build variables.

513 starsLast commit 15 days agoLatest v4.0.0
C
66
/ 100
Security 54Maintenance 83Popularity 58Reliability 70

Security signals

OpenSSF Scorecard5.7 / 10
SECURITY.md presentNo
Immutable releasesNot enabled
Known vulnerabilities1 advisory(ies)
  • CVE-2021-32074high

    Vault GitHub Action did not correctly mask multi-line secrets in output

    Published May 24, 2022

How to use it safely

Recommended: pin to commit SHA
uses: hashicorp/vault-action@892a26828f195e65540a40b4768ae4571f51ebfc # v4.0.0

Mutable tags like v4.0.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: hashicorp/vault-action@892a26828f195e65540a40b4768ae4571f51ebfc # v4.0.0

Score breakdown

Security (35%)54
Popularity (20%)58
Maintenance (30%)83
Reliability (15%)70

Add this badge to your README

ActionRank grade badge for HashiCorp Vault
Markdown
[![ActionRank](https://actionrank.dev/api/badge/hashicorp-vault-action)](https://actionrank.dev/actions/hashicorp-vault-action)
HTML version
HTML
<a href="https://actionrank.dev/actions/hashicorp-vault-action"><img src="https://actionrank.dev/api/badge/hashicorp-vault-action" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for HashiCorp Vault

We'll email you only if HashiCorp Vault becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address