Highlights
Token Privilege Escalation: 1 prior fix. Scrutinize any change in this area.
Actions: most-fixed (1 issue). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Token Privilege Escalation: Overly permissive OIDC token generation scopes allow any runner job in the workflow to access privileged tokens, increasing the blast radius of any compromised dependencies or execution steps in the pipeline. Restricting permissions to job-level definitions mitigates this access.