bug-review
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomaly.github/workflows/bug-review-resolve.yml
LOWAnomalyLOW
.github/workflows/bug-review-resolve.yml
The workflow is intended to track bug-review resolutions and update repository data after merged pull requests. It contains no evident malware in the provided YAML, but it executes repository-controlled scripts with GH_TOKEN and contents: write permission, then pushes their modifications. This is a significant supply-chain risk if those scripts or checked-in files can be altered by an attacker. Review and pin the scripts, restrict the token permissions where possible, quote shell expansions, and consider preventing automatic pushes from untrusted repository content.
Confidence: 97%Severity: 68%
Audit Metadata