depot-github-actions
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
SecuritySecurityevals/fixtures/unsafe-pull-request-target.yml
MEDIUMSecurityMEDIUM
evals/fixtures/unsafe-pull-request-target.yml
This workflow is structurally high-risk: it uses pull_request_target and then checks out and executes a script from the untrusted PR head commit (./from-pull-request.sh). This combination commonly enables arbitrary command execution in a higher-trust context, potentially exposing the GitHub token/secrets depending on repository permission settings. The exact maliciousness cannot be confirmed without reviewing from-pull-request.sh, but the supply-chain security risk is elevated based on the orchestration pattern.
Confidence: 74%Severity: 85%
Audit Metadata