lokalise-deploy-integration
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/implementation-guide.md
LOWAnomalyLOW
references/implementation-guide.md
No clear malicious payload or intentional data exfiltration is present. The main risks are unpinned and unchecked executable downloads, leakage of Lokalise credentials through Docker build arguments, weak shell quoting, and insufficient validation of downloaded archives and locale input. Pin the CLI version, verify checksums or signatures, use secret mounts rather than ARG values, quote and validate shell inputs, and restrict OTA token permissions.
Confidence: 96%Severity: 67%
Audit Metadata