Skip to content

runner token detection

runner-token-detection is a medium severity check in the devops category, written in go. Its source is templates/devops/github/runner-token-detection.go in cert-x-gen-templates.

Field Value
Id runner-token-detection
Severity medium (the fallback: the file names no severity the engine recognises)
Language go
Category devops
Author not recorded
Template version not recorded
Confidence not recorded
CVSS not recorded
Weakness not recorded
Tags not recorded
Target kind not recorded
Oracle not recorded

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info runner-token-detection

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.