Skip to content

[oblt-aw][security] SEC-022 — findings (2026-05-09) #829

@elastic-vault-github-plugin-prod

Description

Security findings (SEC-022)

Analysis date: 2026-05-09
Occurrences: 4

Details

  1. .github/workflows/oblt-aw-ingress.yml — line 42medium — zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  2. .github/workflows/oblt-aw-ingress.yml — line 105medium — zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  3. .github/workflows/oblt-aw-ingress.yml — line 139medium — zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  4. .github/workflows/oblt-aw-ingress.yml — line 176medium — zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)


Generated by oblt-aw security detector. Rules: security-scanning-ruleset (SEC-001–SEC-044, aligned with observability-robots#3758).

Metadata

Metadata

Assignees

No one assigned

    Labels

    oblt-aw/ai/fix-readyIssue has been triaged and is ready for automated fixingoblt-aw/detector/securitySecurity-related signal detected by automated workflowoblt-aw/triage/security-secretsIssue triaged as security-related (secrets)

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions