lov-any2pdf
Warn
Audited by Socket on Sep 30, 2026
1 alert found:
SecuritySecurity.github/workflows/release.yml
MEDIUMSecurityMEDIUM
.github/workflows/release.yml
The workflow has a significant command-injection risk because a manually supplied tag is interpolated into shell scripts. The fixed GITHUB_OUTPUT delimiter also allows crafted changelog content to alter step outputs. These are workflow security weaknesses with potential impact through the release-writing permission; the fragment does not itself establish malicious intent.
Confidence: 98%Severity: 78%
Audit Metadata