ort-release-notes
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow reads release-note primary inputs from first-party generated contributor artifacts in
resolved_output_dir/detail.csv/logs.txtproduced bytools/python/compile_contributors.py, which in turn compiles from commit history and PR metadata, so it does not ingest arbitrary outsider-authored free text directly via a monitored queue/feed without first selecting/deriving specific internal artifacts.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata