github-release

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/ci-workflow-templates.md

The fragment is release-workflow documentation with no direct evidence of malware or intentional data theft. It presents legitimate SBOM, provenance, and signing practices, but has meaningful workflow security weaknesses: mutable external references, broad job permissions, and non-enforcing tag signature verification. Pin reusable workflows and actions to trusted commit SHAs, make signature verification fail closed, and minimize permissions per job. The security risk concerns CI supply-chain exposure rather than malicious behavior in this fragment.

Confidence: 97%Severity: 55%
AnomalyLOW
templates/release-typo3.yml

The workflow appears intended to release an extension and publish it to the TYPO3 Extension Repository. No direct malware, credential theft, obfuscated code, shell execution, or suspicious network destination is present in this file. The primary security risk is supply-chain exposure from invoking external reusable workflows at the mutable `main` branch, combined with write permissions, OIDC access, and publishing secrets. Pin the workflows to reviewed immutable commit SHAs and minimize permissions where possible.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 24, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/netresearch%2Fgithub-release-skill%2Fgithub-release%2F@65ccb69aa57f7ec77d78f1a5c1a009e146f4da0cd6b12ed704a036d3922a2caf
Security Audit — socket — github-release