Skip to content

Code Injection vulnerability in getsentry/sentry-python .github/workflows/update-tox.yml #6170

@linear-code

Description

@linear-code

Repo: getsentry/sentry-python
Confidence: High
Severity: High
Weakness: yaml.github-actions.security.github-script-injection.github-script-injection


To reduce risk of accidental information disclosure, we are intentionally not exposing full vulnerability details here
Please see the parent ticket or Semgrep Console for more details: https://semgrep.dev/orgs/sentry/findings/768520727

Metadata

Metadata

Assignees

No one assigned
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions