Skip to content

ci: wire the coco-dev-versions and import-specifiers drift checks int…

Superagent Security / Superagent Supply Chain Scan failed Jul 30, 2026 in 9s

Supply chain risks detected

3 actionable risks across 2 changed dependencies.

Details

Dependency changes

  • actions/cache/restore (github-action) added 55cc8345863c7cc4c66a329aec7e433d2d1c52a9
  • codecov/codecov-action (github-action) added fb8b3582c8e4def4969c97caa2f19720cb33a72f

Actionable risks

  • HIGH: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 — Detects keylogging and input capture patterns. Location: cache-55cc8345863c7cc4c66a329aec7e433d2d1c52a9/dist/restore-only/index.js. Rules: threat-runtime-keylogging
  • HIGH: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 — Detects keylogging and input capture patterns. Location: cache-55cc8345863c7cc4c66a329aec7e433d2d1c52a9/dist/restore-only/index.js. Rules: threat-runtime-keylogging
  • HIGH: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 — Detects keylogging and input capture patterns. Location: cache-55cc8345863c7cc4c66a329aec7e433d2d1c52a9/dist/restore-only/index.js. Rules: threat-runtime-keylogging