Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Add Static Security Analysis of GitHub Actions Workflows#4606

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
Bibo-Joshi merged 7 commits intomasterfromzizmor
Dec 13, 2024

Conversation

Bibo-Joshi
Copy link
Member

@Bibo-JoshiBibo-Joshi commentedDec 13, 2024
edited
Loading

Inspired by

Edit:

  1. I tested that the modified pypi release workflows still work correctly
  2. I decided to set up a workflow for this instead of using pre-commit because
    1. this enables to use theonline audits
    2. workflows are rarely updated so that adding a pre-commit hook for that seems like an unnecessary additional install step on local end to me
  3. As far as I see, dependabot is able to update actions that are pinned with a sha

@Bibo-JoshiBibo-Joshi added ⚙️ securityaffected functionality: security 🔗 github-actionsrelated technology: github-actions ⚙️ ci-cidaffected functionality: ci-cid labelsDec 13, 2024
@github-advanced-security

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear onthis overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check outthe documentation.

@Bibo-JoshiBibo-Joshi merged commit4afe174 intomasterDec 13, 2024
24 of 25 checks passed
@Bibo-JoshiBibo-Joshi deleted the zizmor branchDecember 13, 2024 21:16
@github-actionsgithub-actionsbot locked and limited conversation to collaboratorsDec 21, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account?Sign in.
Reviewers
No reviews
Assignees
No one assigned
Labels
⚙️ ci-cidaffected functionality: ci-cid🔗 github-actionsrelated technology: github-actions⚙️ securityaffected functionality: security
Projects
None yet
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

1 participant
@Bibo-Joshi

[8]ページ先頭

©2009-2025 Movatter.jp