Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

chore: disable autoupgrade of GH Actions version upgrades#21019

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
jdomeracki-coder merged 5 commits intomainfromgha-dependabot-automerge
Dec 1, 2025

Conversation

@jdomeracki-coder
Copy link
Contributor

Copy link
Member

@matifalimatifali left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others.Learn more.

LGTM.

@github-actionsgithub-actionsbot locked and limited conversation to collaboratorsDec 1, 2025
Copilot finished reviewing on behalf ofmatifaliDecember 1, 2025 11:38
@jdomeracki-coder
Copy link
ContributorAuthor

Gentleman, that was a missclick

@jdomeracki-coder
Copy link
ContributorAuthor

Great example of how easy it is to introduce security hotspots

info[template-injection]: code injection via template expansion  --> ./.github/workflows/dependabot.yaml:50:21|49|         run:||         --- info: this run block50|if ["${{ steps.metadata.outputs.package-ecosystem }}"="github-actions" ];then|                     ---------------------------------------- info: may expand into attacker-controllable code|   = note: audit confidence → Low   = note: this finding has an auto-fix

https://github.com/coder/coder/actions/runs/19821110267/job/56783487704?pr=21019#step:12:114

Even though in this instance it's extremely unlikely that the value would be controlled by an attacker, Zizmor did a great job of catching this

@jdomeracki-coder
Copy link
ContributorAuthor

Need to verify why the lint job keeps on failing, doesn't seem to be security related:
https://github.com/coder/coder/actions/runs/19821553219/job/56785762019?pr=21019

@jdomeracki-coderjdomeracki-coder merged commitcbb0952 intomainDec 1, 2025
28 checks passed
@jdomeracki-coderjdomeracki-coder deleted the gha-dependabot-automerge branchDecember 1, 2025 14:09
Sign up for freeto subscribe to this conversation on GitHub. Already have an account?Sign in.

Reviewers

@dannykoppingdannykoppingdannykopping left review comments

@matifalimatifalimatifali approved these changes

Copilot code reviewCopilotAwaiting requested review from Copilot

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

4 participants

@jdomeracki-coder@dannykopping@matifali

[8]ページ先頭

©2009-2025 Movatter.jp