Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 96% confidence
- Finding
The manifest describes building images, scanning, pushing to a registry, and generating deployment configuration, but it provides no explicit warning, consent checkpoint, or safety controls for these system-impacting actions. In this context, the workflow can move from untrusted user input to deployable artifacts and publication targets, increasing the risk of unintended release, infrastructure impact, or supply-chain exposure.
- Content
