github-actions[bot]
published Jun 25, 2026, 3:23 AM · updated Jun 25, 2026, 3:23 AM
Daily Runtime Threat Scan
Runtime threat scan complete — focus area: setup-cli/. Scanned 3 files (action.yml, install.sh, install_test.sh), no hidden files. All 3 independent LLM judges returned clean. All network calls confined to github.com and api.github.com for github/gh-aw releases only; GH_TOKEN passed to gh CLI subprocess (standard practice), never exfiltrated; SHA256 checksum verification on by default; no obfuscation, eval, base64 blobs, persistence, privilege escalation, or third-party domains detected. Next scan will focus on setup/.
Generated from Daily Runtime Threat Scan · 200.5 AIC · ⊞ 36.4K · ◷