← Scan another repo

github.com/nilbuild/developer-roadmap

@ 8df748dca806

Submitted 8/4/2026, 10:25:51 AM · Status: ok

Risk grade
B
26 / 100
Findings
13
0 critical0 high13 medium0 low0 info0 on CISA KEV0ATT&CK
Showing 13 of 13 findings

Findings

  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Sends Daily AWS Costs to Slack)
    checkov.github/workflows/aws-costs.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Cleanup Orphaned Content)
    checkov.github/workflows/cleanup-orphaned-content.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Close PRs with Feedback)
    checkov.github/workflows/close-feedback-pr.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Clears API Cloudfront Cache)
    checkov.github/workflows/cloudfront-api-cache.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Clears Frontend Cloudfront Cache)
    checkov.github/workflows/cloudfront-fe-cache.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Label Issue)
    checkov.github/workflows/label-issue.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Sync Content to Repo)
    checkov.github/workflows/sync-content-to-repo.yml:0
  • Ensure top-level permissions are not set to write-all
    Ensure top-level permissions are not set to write-all on on(Sync Repo to Database)
    checkov.github/workflows/sync-repo-to-database.yml:0
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Cleanup Orphaned Content)
    checkov.github/workflows/cleanup-orphaned-content.yml:6
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Sync Content to Repo)
    checkov.github/workflows/sync-content-to-repo.yml:6
  • The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty.
    The build output cannot be affected by user parameters other than the build entry point and the top-level source location. GitHub Actions workflow_dispatch inputs MUST be empty. on on(Sync Repo to Database)
    checkov.github/workflows/sync-repo-to-database.yml:6
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgreproadmaps/php/content/mysqli@YLuo0oZJzTCoiZoOSG57z.md:9
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepscripts/sync-repo-to-database.ts:22

This report is public.