Skip to content

Scanning with Grype flags Critical Vulnerability GHSA-7v2w-v6hq-8f3q #288

Description

I am implementing some security checking to GitHub Actions before they can be used.
I have scanned this Action with Grype and it is flagging a GitHub Malware alert against all versions of the Action.

GHSA-7v2w-v6hq-8f3q

The Alert is from 2022 and doesn't seem to have any specific information in it, but claims it is not fixed. Could you tell me if whatever the report is for has been remediated or is the vulnerability still present?

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions