dev-context-engineering
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyassets/fca-compliance-gate.yml
LOWAnomalyLOW
assets/fca-compliance-gate.yml
The workflow is a legitimate compliance-gate scaffold and contains no evident malicious behavior or intentional data theft. It has meaningful supply-chain and CI correctness risks: mutable third-party action references, runtime installation of unpinned tools, swallowed dependency-audit failures, and omission of dependency-scan from the blocking summary condition. Pin actions and tools to trusted immutable versions, quote file variables, generalize branch handling, and make dependency findings fail the gate when required.
Confidence: 97%Severity: 58%
Audit Metadata