spec-forge-cli
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomaly.releaserc.json
LOWAnomalyLOW
.releaserc.json
No explicit malicious code or secrets are present in the provided semantic-release configuration fragment. The dominant risk signal is that the release pipeline executes multiple custom local Node scripts via @semantic-release/exec during both prepare and publish phases, and the resulting artifacts are uploaded and published. This warrants direct review and integrity verification of scripts/release/*.mjs to rule out tampering, credential misuse, unexpected network activity, or backdoored artifacts.
Confidence: 56%Severity: 62%
Audit Metadata