deployment-automation
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/github-actions-deployment-workflow.md
LOWAnomalyLOW
references/github-actions-deployment-workflow.md
No clear malware, credential theft, data exfiltration, destructive behavior, or backdoor is present. The primary risks are deployment configuration errors, mutable third-party tooling, unpinned external Helm content, and direct shell interpolation of secret-controlled values. The workflow should pin actions and kubectl to trusted commit or version identifiers, pin the Helm chart or digest, validate and safely quote inputs, and correct the environment-selection logic.
Confidence: 97%Severity: 58%
Audit Metadata