Scanning with Grype flags Critical Vulnerability GHSA-7v2w-v6hq-8f3q
- Dominant language
- TypeScript
- Stars
- 158
- Forks
- 72
- Avg merge
- 5d 23h
- Merged PRs (30d)
- 3
Description
I am implementing some security checking to GitHub Actions before they can be used.
I have scanned this Action with Grype and it is flagging a GitHub Malware alert against all versions of the Action.
[GHSA-7v2w-v6hq-8f3q](https://github.com/advisories/GHSA-7v2w-v6hq-8f3q)
The Alert is from 2022 and doesn't seem to have any specific information in it, but claims it is not fixed. Could you tell me if whatever the report is for has been remediated or is the vulnerability still present?
Thanks
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the linked GHSA advisory and the Grype scan described in the issue. No files or tests are named; determine whether the reported vulnerability still affects the setup-kubectl Action, and document whether it has been remediated.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, kubernetes, typescript
- Domain
- ci-cd, devops, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100