github-workflows-pgpm

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment presents a coherent and purpose-aligned CI workflow blueprint for PGPM-based PostgreSQL testing, with standard tooling and containerized DB services. Security concerns are moderate and revolve around secret handling and reliance on external images. No explicit malicious behavior detected in the fragment. Recommend validating image provenance, implementing secret masking and strict access controls, and using pinned image digests and CI secrets management to reduce supply-chain risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive-skills%2Fgithub-workflows-pgpm%2F@bd04ee4a261631a1cc726898952883fc65edd604
Security Audit — socket — github-workflows-pgpm