[StepSecurity] ci: Harden GitHub Actions #5147
build.yml
on: pull_request
Config
/
...
/
Convert platforms CSV to JSON
7s
Artifact key
10s
Docker secrets
8s
Foundry secrets
8s
Diagnostics
/
Diagnostics
25s
Matrix: Build platform
Waiting for pending jobs
Matrix: Bill of Materials
Waiting for pending jobs
Publish docs
/
publish
Annotations
4 errors and 12 warnings
Docker secrets
Process completed with exit code 1.
|
Foundry secrets
Process completed with exit code 1.
|
Artifact key
Process completed with exit code 1.
|
Lint / Lint sources
Process completed with exit code 1.
|
Docker secrets
Set the DOCKER_USERNAME secret.
|
Docker secrets
Set the DOCKER_PASSWORD secret.
|
Docker secrets
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
|
Foundry secrets
Set the FOUNDRY_USERNAME secret.
|
Foundry secrets
Set the FOUNDRY_PASSWORD secret.
|
Foundry secrets
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
|
Config / Convert CSV to JSON / Convert platforms CSV to JSON
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
|
Artifact key
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
|
Artifact key
Set the ARTIFACT_KEY secret.
|
Lint / Lint sources:
.github/workflows/scorecards.yml#L31
31:84 [comments] too few spaces before comment
|
Lint / Lint sources:
.github/workflows/label-automerge.yml#L22
22:84 [comments] too few spaces before comment
|
Lint / Lint sources
Restore cache failed: Dependencies file is not found in /home/runner/work/foundryvtt-docker/foundryvtt-docker. Supported file pattern: go.sum
|