Skip to content

Command Injection vulnerability in getsentry/opentelemetry-js .github/workflows/changelog.yml #20574

@linear-code

Description

@linear-code

Repo: getsentry/opentelemetry-js
Confidence: High
Severity: High
Weakness: yaml.github-actions.security.run-shell-injection.run-shell-injection


To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: https://semgrep.dev/orgs/sentry/findings/767832056

Metadata

Metadata

Assignees

No one assigned
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions