“Write workflows scripting the GitHub API in JavaScript”
Local reference
Suspicious dependency
Inferred
Referenced by 6 samples
- benign github.com-MarineYachtRadar-mayara-server-v3.10.0+incompatible.zip fetched
- benign v0.26.2.tar.gz fetched
- benign github.com-cloudquery-cloudquery-plugins-source-stripe-v0.0.0-20230124104413-1fe937b2477b.zip fetched
- v1.8.3.zip fetched
- benign github.laiyagushi.com-sveltinio-sveltin-v0.6.1.zip fetched
- benign v0.29.0.zip fetched
Well-known
notable severity, 99% confident.
lib/web
whatwg-url basicURLParse API marker
Micro-behaviors
notable severity, 96% confident.
communications/http
Access-token field reference
notable severity, 94% confident.
communications/http/request
Calls a response JSON parser
notable severity, 96% confident.
communications/http/services
GitHub GraphQL API endpoint
notable severity, 90% confident.
communications/http/url
References a public code-forge URL
notable severity, 90% confident.
communications/socket
Node TLS check disabled by option
notable severity, 90% confident.
data
Creates Node.js Buffer from UTF-8 text
notable severity, 92% confident.
data/control-flow
CommonJS module re-exports required package
notable severity, 90% confident.
data/decode
JavaScript hex-to-integer conversion
notable severity, 95% confident.
data/encode
Encodes Node.js Buffer output as Base64
notable severity, 90% confident.
data/string
Reverses string with split reverse join
notable severity, 90% confident.
fs/file
Calls readFileSync
notable severity, 96% confident.
os/env/vars
Actions OIDC token request env vars
notable severity, 95% confident.
process/interpreter
JavaScript AsyncFunction compiles code
Metadata
notable severity, 95% confident.
build
Code follows a source map directive
notable severity, 94% confident.
file
Long JavaScript string concatenation chain
notable severity, 99% confident.
file/profile
Escaped Unicode script codepoint in source
notable severity, 95% confident.
library
Preserves original JavaScript console methods
notable severity, 90% confident.
package
Package uses git hooks tooling
notable severity, 95% confident.
package/files
JavaScript package file under the dist tree
20 of 51 traits shown
Identity
| SHA-256 | 7063fc1768b0059f0b1634b2a07f00da5e66ff7165da1e61eb69cb439624ba96 |
|---|---|
| Canonical SHA-256 | 36c571276d2e4e879ca3d3162ad4c84c3f4de3a1f88a80714bfe5d50354d5326 |
| Filename | github-script@v5 |
| Package | actions/github-script |
| Version | v5 |
| PURL | pkg:github/actions/github-script@v5 |
Origin
| Source | x |
|---|---|
| Feed | pkg.go.dev |
| Ecosystem | github |
| Domain | github.com |
| URL | https://codeload.github.com/actions/github-script/tar.gz/v5 |
Timeline
| First seen | 12 Aug 2026 18:20 UTC |
|---|---|
| First analyzed | 12 Aug 2026 18:21 UTC |
| Last analyzed | 21 Aug 2026 10:49 UTC |
| Last updated | 21 Aug 2026 10:53 UTC |
Labeling
| Label | unknown |
|---|
Not seeing what you expected? Let us know