base-images-and-rpms
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
AnomalyAnomalyscripts/base-images-and-rpms.sh
LOWAnomalyLOW
scripts/base-images-and-rpms.sh
No direct malware indicators (obfuscation, eval, exfiltration, backdoor behaviors) are evident in this bash fragment. However, it is a high-impact automation orchestrator that downloads and executes remote GitLab scripts and auto-installs a runnable tool from a GitHub main-branch zip without pinning or integrity checks. If upstream scripts/tools are compromised or if an operator supplies a malicious path, this script can execute arbitrary code and perform git changes/PR creation. Treat as a supply-chain execution risk; verify and pin upstream script/tool versions and add integrity verification before use.
Confidence: 65%Severity: 60%
Audit Metadata