ci-cd-specialist
Warn
Audited by Snyk on Mar 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The GitHub Actions workflow includes runtime "uses" references that fetch and execute remote action code (e.g., actions/checkout@v4 -> https://github.com/actions/checkout), which are required steps in the workflows and thus execute external code at runtime.
Audit Metadata