github-actions-nx
Warn
Audited by Snyk on Mar 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The workflows invoke third‑party GitHub Action repositories that are fetched and executed at runtime (e.g., actions/checkout@v4, nrwl/nx-set-shas@v4, actions/setup-node@v4, actions/setup-go@v5, geekyeggo/delete-artifact@v5), which constitute runtime external dependencies that execute remote code on the runner.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata