Azure / Azure/setup-kubectl

Scanning with Grype flags Critical Vulnerability GHSA-7v2w-v6hq-8f3q

Open
#288 0 comments 0 reactions 0 assignees View on GitHub
need-to-triage
Dominant language
TypeScript
Stars
158
Forks
72
Avg merge
5d 23h
Merged PRs (30d)
3

Description

I am implementing some security checking to GitHub Actions before they can be used.
I have scanned this Action with Grype and it is flagging a GitHub Malware alert against all versions of the Action.

[GHSA-7v2w-v6hq-8f3q](https://github.com/advisories/GHSA-7v2w-v6hq-8f3q)

The Alert is from 2022 and doesn't seem to have any specific information in it, but claims it is not fixed. Could you tell me if whatever the report is for has been remediated or is the vulnerability still present?

Thanks

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the linked GHSA advisory and the Grype scan described in the issue. No files or tests are named; determine whether the reported vulnerability still affects the setup-kubectl Action, and document whether it has been remediated.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, kubernetes, typescript
Domain
ci-cd, devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.