Audit a CI workflow for what it leaves movable or undeclared. Reports actions pinned to a tag rather than a commit - a tag can be moved by whoever owns the action, so the code a step runs can change without this file changing - missing permissions and timeouts, a job depending on one that is not declared, a pull_request_target trigger, and an expression interpolated straight into a shell command.
| Network | Scheme | Amount | Pay To |
|---|---|---|---|
| Base | exact | $0.12 USDC | 0x25e8...9608 |