Conversation
7222c6d to
1fd3787
Compare
|
Ooh fancy, thank you! That looks great :) Action safetyI am a bit scared by the third-party action From what I learned, this is not safe as it is only referencing a version, not a commit hash. That way the author (or a malicious actor who got access to the author's repo) could publish a malicious Could you specify a specific git commit instead? (I was hoping that action was easy to review but it is three gazillion node packages. I guess we can assume that it is currently safe to use though... :} ) |
|
I get your point but it sounds to me an overkill security safety since it only manipulate documentation files with no content write and no access to secrets. Well it could publish on GH Pages. Nevertheless, I've changed to the commit hash. |
for more information, see https://pre-commit.ci
affc476 to
ca23f88
Compare
jmkerloch
left a comment
There was a problem hiding this comment.
We now just have to add the documentation for the plugin use 😄
Now you know how much I know about actions and permissions ;D Thank you |
|
Would it make sense to update the |
No worries, your project, your rules and indeed it's wiser than the reverse :).
Good idea! Done in latest commit! |
Render:
Capture.video.du.2025-03-26.18-34-45.mp4
❤️ Funded by Oslandia