bump-version
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN: The code fragment describes a self-contained, legitimate release automation workflow for version bumps and changelog management. It relies on standard Git operations and file edits, with no credential handling, network exfiltration, or executable downloads. The only notable aspect is an unusually strong, non-functional safety/consistency admonition about preserving changelog history, which is within user guidance for maintaining changelog integrity. Overall, the footprint is coherent with its stated purpose and does not introduce supply-chain security risks.
Confidence: 75%Severity: 75%
Audit Metadata