github-workflows-pgpm

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment presents a coherent and purpose-aligned CI workflow blueprint for PGPM-based PostgreSQL testing, with standard tooling and containerized DB services. Security concerns are moderate and revolve around secret handling and reliance on external images. No explicit malicious behavior detected in the fragment. Recommend validating image provenance, implementing secret masking and strict access controls, and using pinned image digests and CI secrets management to reduce supply-chain risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:56 AM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive-skills%2Fgithub-workflows-pgpm%2F@bd04ee4a261631a1cc726898952883fc65edd604