An open API service providing security vulnerability metadata for many open source software ecosystems.

Critical
about 1 month ago

Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses GSA_kwCzR0hTQS13cHFyLTZ2NzgtanI1Z84ABVxF

actions, npm google-github-actions/run-gemini-cli, @google/gemini-cli
Critical
2 months ago

Trivy ecosystem supply chain was briefly compromised GSA_kwCzR0hTQS02OWZxLXhwNDYtNngyM84ABUGq

actions, go aquasecurity/setup-trivy, aquasecurity/trivy-action, github.com/aquasecurity/trivy
Moderate
over 2 years ago

Actions expression injection in `filter-test-configs` (`GHSL-2023-181`) GSA_kwCzR0hTQS1odzZyLWc4Z2otMjk4N84AA1lL

actions https://github.com/pytorch/pytorch/.github/actions/filter-test-configs

Filter by Severity

Filter by Package

Filter by Repository

https://github.com/tj-actions/changed-files 2 https://github.com/tj-actions/branch-names 2 https://github.com/rlespinasse/github-slug-action 2 https://github.com/step-security/harden-runner 2 https://github.com/SonarSource/sonarqube-scan-action 2 https://github.com/kartverket/github-workflows 1 https://github.com/OZI-Project/publish 1 https://github.com/fish-shop/syntax-check 1 https://github.com/ultralytics/actions 1 https://github.com/pytorch/pytorch 1 https://github.com/j178/prek-action 1 https://github.com/buildalon/setup-steamcmd 1 https://github.com/actions/download-artifact 1 https://github.com/embano1/wip 1 https://github.com/hashicorp/vault-action 1 https://github.com/check-spelling/check-spelling 1 https://github.com/lycheeverse/lychee-action 1 https://github.com/broadinstitute/cromwell 1 https://github.com/Azure/setup-kubectl 1 https://github.com/RageAgainstThePixel/setup-steamcmd 1 https://github.com/github/codeql-action 1 https://github.com/pypa/gh-action-pypi-publish 1 https://github.com/dawidd6/action-download-artifact 1 https://github.com/atlassian/gajira-create 1 https://github.com/tj-actions/verify-changed-files 1 https://github.com/actions/runner 1 https://github.com/afichet/openexr-viewer 1 https://github.com/bullfrogsec/bullfrog 1 https://github.com/some-natalie/ghas-to-csv 1 https://github.com/gradle/gradle-build-action 1 https://github.com/BoldestDungeon/steam-workshop-deploy 1 https://github.com/reviewdog/reviewdog 1 https://github.com/canonical/get-workflow-version-action 1