automate-npm-release

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
EXAMPLE_WORKFLOW.yml

No direct malicious behavior is evident in this workflow. It implements a conventional npm release pipeline, but it has meaningful supply-chain exposure: mutable GitHub Action tags, unpinned npx execution with a repository token, and elevated write and OIDC permissions. Pin actions and changelogithub to trusted immutable versions, minimize permissions, and protect release tags before using this workflow.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 28, 2026, 09:57 AM
Package URL
pkg:socket/skills-sh/jd-solanki%2Fskills%2Fautomate-npm-release%2F@3ac6b1a5ec0afc9aec32db2dd54bf4a05092cb897ad4f72e69ae2842cbd4996e
Security Audit — socket — automate-npm-release