{
  "ml": {
    "v": "7",
    "id": 78,
    "lvl": -1,
    "conf": 0,
    "prob": 0.000012586514458234888,
    "type": "yaml",
    "version": "v18.18",
    "analyzed_at": "2026-09-21T09:40:47Z"
  },
  "path": "actions-golang@v1",
  "raw": {
    "rev": "30920",
    "files": [
      {
        "id": 145,
        "mol": "O(S)Md(Bk)",
        "pid": 3,
        "rel": "fetched",
        "sha": "90b3ee496d58141560c8f3414d835b940cd429ea2246ecf85c169c686f2a77db",
        "via": "https://codeload.github.com/winchci/actions-golang/tar.gz/v1",
        "path": "pkg:github/winchci/actions-golang@v1",
        "risk": 119,
        "size": 4611,
        "type": "gz",
        "depth": 2,
        "facts": {
          "metrics": {
            "file": {
              "size": 4611,
              "entropy": 7.96
            },
            "binary": {
              "peak_region_bytes": 4611,
              "peak_region_entropy": 7.79
            }
          }
        },
        "traits": [
          {
            "id": "metadata/lang/natural::lang-english--atom-7",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"this\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-3",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"that\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-1",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"the\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-4",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"have\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-6",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"with\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "objectives/supply-chain/hidden-payload/ci::gha-action-yml-manifest",
            "atk": "T1195.002",
            "conf": 0.98,
            "crit": 3,
            "desc": "GitHub Action action.yml manifest",
            "from": [
              {
                "file": 1
              }
            ]
          },
          {
            "id": "objectives/supply-chain/hidden-payload/ci::gha-remote-docker-action",
            "atk": "T1195.002",
            "conf": 0.98,
            "crit": 5,
            "desc": "Action executes an unpinned remote Docker image",
            "from": [
              {
                "file": 146
              }
            ],
            "uses": [
              5,
              10
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-2",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"and\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/lang/natural::lang-english--atom-5",
            "conf": 0.8,
            "crit": 1,
            "desc": "English function-word token \"for\"",
            "from": [
              {
                "file": 2
              }
            ]
          },
          {
            "id": "metadata/package/documentation/source::readme-markdown-basename",
            "conf": 0.99,
            "crit": 2,
            "desc": "README Markdown basename",
            "from": [
              {
                "file": 3
              }
            ]
          },
          {
            "id": "metadata/build/ci/step::gha-remote-docker-image",
            "conf": 0.92,
            "crit": 3,
            "desc": "Action pulls a remote Docker image",
            "from": [
              {
                "file": 1
              }
            ]
          }
        ]
      }
    ]
  }
}