github-actions[bot]
published May 17, 2026, 9:47 PM · updated May 17, 2026, 9:47 PM
Daily Runtime Threat Scan
Security scan complete for focus area: setup/. Scanned action.yml, index.js, post.js, setup.sh, all shell scripts in sh/, and key JavaScript files in js/. All network calls are to github.com releases (for binary downloads) or user-configured OTLP telemetry endpoints. No secret exfiltration, obfuscation, hidden executables, or suspicious payloads detected. Result: clean. Next scan will cover setup-cli/.
Generated from Daily Runtime Threat Scan