-
Notifications
You must be signed in to change notification settings - Fork 1
[oblt-aw][security] SEC-010 — findings (2026-05-05) #788
Copy link
Copy link
Open
Labels
oblt-aw/ai/fix-readyIssue has been triaged and is ready for automated fixingIssue has been triaged and is ready for automated fixingoblt-aw/detector/securitySecurity-related signal detected by automated workflowSecurity-related signal detected by automated workflowoblt-aw/triage/security-injectionIssue triaged as security-related (injection)Issue triaged as security-related (injection)
Metadata
Metadata
Assignees
Labels
oblt-aw/ai/fix-readyIssue has been triaged and is ready for automated fixingIssue has been triaged and is ready for automated fixingoblt-aw/detector/securitySecurity-related signal detected by automated workflowSecurity-related signal detected by automated workflowoblt-aw/triage/security-injectionIssue triaged as security-related (injection)Issue triaged as security-related (injection)
Type
Fields
Give feedbackNo fields configured for issues without a type.
Security findings (SEC-010)
Analysis date: 2026-05-05
Occurrences: 1
Details
.github/workflows/oblt-aw-ingress.yml— line 209 — high — zizmor [template-injection]: code injection via template expansion (https://docs.zizmor.sh/audits/#template-injection)Generated by oblt-aw security detector. Rules: security-scanning-ruleset (SEC-001–SEC-044, aligned with observability-robots#3758).