-
-
Notifications
You must be signed in to change notification settings - Fork 27
Open
Labels
questionFurther information is requestedFurther information is requested
Description
Right now, there's a potential security vulnerability where a rogue commit to the reviewdog library would yield access to my whole codebase.
Is it possible to lock down the reviewdog ref in script.sh to avoid this?
(affects most reviewdog actions, but as brakeman is security-focused, I wanted to start here).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested