cicd-pipeline-setup
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/github-actions-workflow.md
LOWAnomalyLOW
references/github-actions-workflow.md
The workflow does not contain clear evidence of intentional malware or data theft. It has meaningful CI supply-chain and workflow-hardening risks: mutable third-party action references, execution of pull-request-controlled Dockerfile code, and excessive packages: write permission on a job that runs for pull requests. Pin actions to verified commit SHAs, minimize permissions, isolate or avoid Docker builds for untrusted pull requests, and explicitly configure id-token: write for AWS OIDC if required.
Confidence: 96%Severity: 62%
Audit Metadata