LoFP LoFP / t1195

t1195

TitleTags
approved changes by the organization owner. please validate the 'actor' if authorized to make the changes.
authorized github actions runner with no malicious workflow actions.
authorized github repository with no malicious workflow actions.
authorized self-hosted github actions runner.
legitimate ci/cd automation that commits and pushes changes (e.g., auto-formatting, changelog updates, version bumps, dependabot auto-merge) will trigger this alert on first use in a repository. review the repository's workflow configurations to determine if bot pushes are expected.
legitimate ci/cd automation that requires workflow file modifications may trigger this alert if not properly configured with the necessary permissions. review the workflow configuration and ensure the github_token or pat has the required 'workflows' permission if the modification is intentional.
legitimate engineering activity regularly creates workflow yamls. suppress by repository path allowlisting, ci hosts, change windows, or approval timeframes.
trusted solarwinds child processes. verify process details such as network connections and file writes.
unknown
very low. legitimate usage of a file with this exact name is unlikely; validate with repository owners.