GR-CI-001+5
CI workflow pipes a download into a shell
The CI configuration downloads a script and runs it on the build server (GitHub Actions, GitLab CI, Azure Pipelines, ...). That is not the machine of whoever clones the repository, so it weighs little; it still means whoever controls that URL controls the build.
files: .github/workflows/*.yml, .github/workflows/*.yaml, .gitlab-ci.yml, .gitlab/ci/*.yml, .travis.yml, .circleci/*.yml, appveyor.yml, .appveyor.yml, bitbucket-pipelines.yml, .drone.yml, .woodpecker.yml, .woodpecker/*.yml, .buildkite/*.yml, cloudbuild.yaml, cloudbuild.yml, codemagic.yaml, Jenkinsfile, azure-pipelines*.yml, azure-pipelines/*.yml, azure-pipelines/*/*.yml, azure-pipelines/*/*/*.yml, .azure-pipelines/*.yml, .pipelines/*.yml
Social engineering
Asks you to disable your antivirus
Telling users to turn off Windows Defender, add an exclusion or ignore a "false positive" is the signature move of fake cheat, crack and tool repositories: the download would be blocked otherwise.
files: *.md, *.markdown, *.mdown, *.rst, *.adoc, *.asciidoc, *.txt, README*