-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:328
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:270
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:161-163
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:57
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:267
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:74
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:119
-
Dependency advisory GHSA-67mh-4wv8-2f99:pkg:100a52fb5850b2ff8a7f76c7 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: bun.lock
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:219
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:86
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:79-83
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:207
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:316
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:62
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:287
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:337
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:96
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-latest.yml:52
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:250
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:129-131
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:219
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:270
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:193
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:292
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:132
-
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:286
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:218
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:132
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:99
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:205
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:132
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:144
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:108
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:218
-
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:284
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:188
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:109
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:359
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:128
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:79
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:316-318
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:267-269
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:187
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:319
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:74
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:62
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:132
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:207
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:86
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:75
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:132
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:132
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:247
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:219
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:108
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:110-112
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:129
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:63
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-latest.yml:51
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:375
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:205
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:97
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:298
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:208
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:187
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:110
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:215
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:99
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:359-361
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:123
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:87
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:363
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:97
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:96-98
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:161
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:113
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:141
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:98
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:57-59
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:172
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:157
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:157
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:221
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:345
-
zizmor reported cache-poisoning · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release-npm.yml:128
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:133
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:158
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:113
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/release.yml:322