You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bad YAML string/int conversions (these will be annoying to detect, since we'd need to go back up to the original span to see if the deserialized form diverges)
Self-hosted runners are fundamentally insecure when not run ephemerally, but there's no great way to detect this statically. So we'll likely need to make that check a pedantic-only one.
action.yml
) Feature: support auditing (composite) actions #173pull_request_target
workflow_run
: pull_request_target -> dangerous_triggers #33pypa/gh-action-pypi-publish
without trusted publishingrubygems/release-gem
without trusted publishingcontainer
/service
credentialsgh-action-pypi-publish@master
should be@release/v1
.(this should probably be pedantic only)GITHUB_ENV
usage: New audit:GITHUB_ENV
#156ACTIONS_ALLOW_UNSECURE_COMMANDS
#171The text was updated successfully, but these errors were encountered: