devops-automator
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyreferences/github-actions-patterns.yaml
LOWAnomalyLOW
references/github-actions-patterns.yaml
No clear malicious behavior is present in this workflow. The main security concerns are CI supply-chain and privilege-boundary weaknesses: mutable third-party action references, execution of pull-request-controlled code, and registry write permissions with image pushing not restricted to trusted branches. The staging kubeconfig handling also has correctness and secret-lifecycle issues. Pin actions to verified commit SHAs, prevent untrusted pull requests from receiving write-capable build behavior or pushing images, and persist or securely manage KUBECONFIG only where needed.
Confidence: 97%Severity: 68%
Audit Metadata