dev-git-workflow
Audited by Socket on Sep 23, 2026
2 alerts found:
SecurityAnomalyNo clear malicious payload or intentional data theft is present. The configuration has material CI supply-chain and isolation risks: unpinned npm installation and container tags, execution of arbitrary project/dependency scripts, and especially Docker socket exposure to a third-party code-quality image. Security checks are weakened by allow_failure and an unreliable secret-detection command. Pin dependencies and images by lockfile/version or digest, avoid mounting the host Docker socket, use a hardened isolated runner, improve secret scanning, and enforce critical scan failures.
No direct malware or intentional sabotage is evident in this workflow. The main risks are CI supply-chain exposure from mutable third-party action references, execution of pull-request-controlled npm scripts, dynamically installed tooling, and potentially excessive GITHUB_TOKEN permissions. Pin actions to verified commit SHAs, declare minimal permissions, use locked dependencies, and ensure fork PRs cannot access sensitive credentials.