dagger
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill clearly fetches and runs external container images at runtime (e.g., "node:22-slim", "postgres:18", "timescale/timescaledb-ha:pg18.3-ts2.25.2-all", "redis:7-alpine") and invokes the GitHub Action "dagger/dagger-for-github@v8.4.1", all of which are required runtime dependencies that download and execute remote code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata