Skip to content

Commit 1048e11

Browse files
committed
Make this a pedantic audit
1 parent a9d18a1 commit 1048e11

File tree

3 files changed

+4
-1
lines changed

3 files changed

+4
-1
lines changed

src/audit/secrets_outside_environment.rs

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ use github_actions_models::{
44
};
55

66
use super::{Audit, audit_meta};
7-
use crate::{finding::Confidence, AuditState, AuditLoadError};
7+
use crate::{finding::Confidence, AuditState, AuditLoadError, Persona};
88

99
pub(crate) struct SecretsOutsideEnvironment;
1010

@@ -73,6 +73,7 @@ impl SecretsOutsideEnvironment {
7373
.add_location(step.location().primary())
7474
.confidence(Confidence::High)
7575
.severity(crate::finding::Severity::High)
76+
.persona(Persona::Pedantic)
7677
.build(step.workflow())?,
7778
);
7879
}

src/main.rs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -530,6 +530,7 @@ fn run() -> Result<ExitCode> {
530530
register_audit!(audit::overprovisioned_secrets::OverprovisionedSecrets);
531531
register_audit!(audit::unredacted_secrets::UnredactedSecrets);
532532
register_audit!(audit::forbidden_uses::ForbiddenUses);
533+
register_audit!(audit::secrets_outside_environment::SecretsOutsideEnvironment);
533534

534535
let mut results = FindingRegistry::new(&app, &config);
535536
{

tests/integration/snapshot.rs

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -654,6 +654,7 @@ fn secrets_outside_environment() -> Result<()> {
654654
insta::assert_snapshot!(
655655
zizmor()
656656
.input(input_under_test("secrets-outside-environment.yml"))
657+
.args(["--persona=pedantic"])
657658
.run()?
658659
);
659660

0 commit comments

Comments
 (0)