chore(deps): bump actions/checkout from 6.1.0 to 7.0.1 - #4
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump actions/checkout from 6.1.0 to 7.0.1#4dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Annotations
7 errors and 3 warnings
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L6
High-entropy encoded payload added — New or changed files contain unusually long Base64/hex-like blobs.
|
|
Run the repository Action
Maintainer set changed — A publisher or maintainer transition can be legitimate%2C but it is a high-value supply-chain review point.
|
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L8
New network capability — The updated package introduces the network capability%2C which was not detected in the previous version.
|
|
Run the repository Action:
fixtures/risky-v2/package.json#L0
New postinstall lifecycle script — npm may execute this lifecycle hook during installation or package preparation.
|
|
Run the repository Action:
fixtures/risky-v2/vendor/prebuild.node#L0
1 new native binary file — Binary payloads are difficult to review with ordinary source diffs and may execute outside JavaScript controls.
|
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L11
New dynamic code execution — The updated package introduces the dynamic-code capability%2C which was not detected in the previous version.
|
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L2
New child process capability — The updated package introduces the child_process capability%2C which was not detected in the previous version.
|
|
Run the repository Action:
fixtures/risky-v2/package.json#L0
Package repository changed — The published repository metadata changed between versions.
|
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L5
1 new network destination — The update adds URL literals for%3A collector.example.invalid.
|
|
Run the repository Action:
fixtures/risky-v2/scripts/install.js#L3
New filesystem capability — The updated package introduces the filesystem capability%2C which was not detected in the previous version.
|
background
wait
wait-all
cancel
parallel
Loading