Skip to content

Update workflow for moar securities#2910

Open
funnelfiasco wants to merge 1 commit intoguacsec:mainfrom
funnelfiasco:zizmor-audits
Open

Update workflow for moar securities#2910
funnelfiasco wants to merge 1 commit intoguacsec:mainfrom
funnelfiasco:zizmor-audits

Conversation

@funnelfiasco
Copy link
Collaborator

  • Update outdated exclusions
  • Add exclusions for unpinned-uses when the action requires tag instead of hash
  • Prevent a cache poisoning attack in the release workflow

Related to #2909

PR Checklist

  • All commits have a Developer Certificate of Origin (DCO) -- they are generated using -s flag to git commit.
  • All new changes are covered by tests
  • If GraphQL schema is changed, make generate has been run
  • If GraphQL schema is changed, GraphQL client updates/additions have been made
  • If OpenAPI spec is changed, make generate has been run
  • If ent schema is changed, make generate has been run
  • If collectsub protobuf has been changed, make proto has been run
  • All CI checks are passing (tests and formatting)
  • All dependent PRs have already been merged

- Update outdated exclusions
- Add exlcusions for unpinned-uses when the action requires tag instead of hash
- Prevent a cache poisoning attack in the release workflow

Signed-off-by: Ben Cotton <ben@kusari.dev>
Copy link
Member

@mihaimaruseac mihaimaruseac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants