figma-deploy-integration
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/google-cloud-run-design-token-api.md
LOWAnomalyLOW
references/google-cloud-run-design-token-api.md
No direct evidence of malicious behavior or intentional obfuscation is present. The configuration performs expected containerization, secret storage, and Cloud Run deployment. The main security risk is that the service is unauthenticated publicly, while its runtime implementation is omitted; application-level authorization and protection of the Figma token require review. The token should also be supplied through a secure CI secret mechanism with shell tracing and log exposure prevented.
Confidence: 94%Severity: 58%
Audit Metadata