cicd-expert
Audited by Socket on Sep 14, 2026
2 alerts found:
SecurityAnomalyThe file contains legitimate CI/CD security guidance and no clear malware or intentional data theft. It does contain materially risky workflow patterns: executing untrusted pull-request code under pull_request_target, using mutable third-party action tags, downloading an unverified latest binary, and granting broad workflow permissions. These issues represent supply-chain and CI compromise risks if copied directly into production. Pin actions and tools to verified immutable versions, avoid executing fork code in privileged workflows, minimize permissions per job, and make policy checks fail closed.
No clear malicious behavior is present. The fragment is a legitimate set of CI/CD examples, but it contains security-sensitive automation: arbitrary repository code execution, privileged Docker/Kubernetes operations, cross-repository writes, token use in command arguments, and numerous floating image/action tags. These are configuration and supply-chain risks requiring hardening, not evidence of malware in this file.