You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ci: github: Harden the test workflow by using runner temp dir
This issue was reported by CodeQL, IMHOI the alert was over reacting
because contents was already extracted in a separate directory (which
is absent in tree, so there is no risk to override)
An extra check would be to verify a signed asset (using GPG),
along a ZWA public key shared in tree.
Potential fix for code scanning alert no. 1: Artifact poisoning
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Relate-to: Z-Wave-Alliance/OSWG#48 (comment)
Signed-off-by: Philippe Coval <[email protected]>
0 commit comments