arvancloud-api
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalyreferences/dns-and-tls.md
LOWAnomalyLOW
references/dns-and-tls.md
The content is operational documentation for ArvanCloud DNS and Let's Encrypt certificate deployment, not apparent malware. The principal security concern is unsafe shell construction in the deployment example: untrusted or compromised deployHooks values can inject commands or cause private keys to be copied to unintended locations. DNS deletion and remote key deployment are powerful but purpose-consistent operations. Configuration values should be strictly validated and shell-escaped, and API keys/private keys should be protected.
Confidence: 96%Severity: 58%
Audit Metadata