Was checking out your repo and ran it through Trustabl. Found 2 findings, both categorized as high risk. A couple of patterns that stood out were network calls without a timeout and the tool fetching a caller-controlled URL, which might be worth a look. Just thought you'd want to know.
Add Trustabl to your CI — trustabl/trustabl-action:
- name: Trustabl scan
uses: trustabl/trustabl-action@v1
Was checking out your repo and ran it through Trustabl. Found 2 findings, both categorized as high risk. A couple of patterns that stood out were network calls without a timeout and the tool fetching a caller-controlled URL, which might be worth a look. Just thought you'd want to know.
Add Trustabl to your CI — trustabl/trustabl-action: