Run zizmor on github actions, pinning all actions#23067
Run zizmor on github actions, pinning all actions#23067oliverguenther wants to merge 8 commits intodevfrom
Conversation
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
machisuji
left a comment
There was a problem hiding this comment.
:+1 LGTM! Although could you please elaborate a bit on the reason behind disabling package manager caching? Yes, it's probably a security issue. But it would just be interesting to see why this was disabled in the commit message, not just that it has been disabled.
|
@machisuji from https://docs.zizmor.sh/audits/#cache-poisoning
We could probably disable this only for dockerization/release processes, and leave the CI runs unchanged, and set it to ignore the respective actions. |
4e52d32 to
3299590
Compare
3299590 to
c8f6c18
Compare
persist-credentials: falsewhere applicablehttps://community.openproject.org/work_packages/74698