gitlab-ci
Warn
Audited by Snyk on Jun 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The docs include CI jobs that fetch and execute remote artifacts at runtime — e.g., pulling and running the container image registry.gitlab.com/gitlab-org/release-cli:latest and running git clone of a remote repository ($UPSTREAM_REPO_URL) which will fetch and execute code in the pipeline.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata