← Scan another repo

github.com/balena-io/etcher

@ 1e2500e4f11c

Submitted 8/4/2026, 10:28:00 AM · Status: ok

Risk grade
F
100 / 100
Findings
268
0 critical2 high263 medium0 low3 info0 on CISA KEV0ATT&CK
Showing 268 of 268 findings

Findings

  • @actions/download-artifact has an Arbitrary File Write via artifact extraction
    grype
  • Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    Shell command built with interpolated input via child_process.exec — command injection risk. Use execFile with an argv array. (First-party socbox; Apache-2.0.)
    semgrepforge.config.ts:143

This report is public.