gitea actions: update / clarify maintenance on them or can we just use github actions instead ? #29406
Labels
issue/needs-feedback
For bugs, we need more details. For features, the feature must be described in more detail
type/proposal
The new feature has not been accepted yet but needs to be discussed first.
gitea actions update clarification
Hi,
not sure whether this is a good feature request but will try anyway (it is more of a proposal).
problem / context:
gitea.com uses github compatible actions fot pipelines. but some / most of the actions offered on gitea.com are outdated and contain vulnerabilities.
example: see below trivy scanning reports on the actions/checkout repo.
i think pulling in some software as part of running a pipeline is ok as long as there is trust on that the code is maintained / safe.
questions:
from what i see each gitea actions repo is a plain mirror of github, but simply not updated ?
suggestions:
can you share some light on whether it's recommeneded to use github actions straight away or share wether there is intention to update the gitea actions ?
or it's perhaps to early to tell (since gitea actions are still work in progress?
other than that: documentation looks great, speed of gitea is excellent so thanks already for that.
Screenshots
The text was updated successfully, but these errors were encountered: