File tree Expand file tree Collapse file tree 2 files changed +14
-5
lines changed Expand file tree Collapse file tree 2 files changed +14
-5
lines changed Original file line number Diff line number Diff line change @@ -533,3 +533,14 @@ fn unredacted_secrets() -> Result<()> {
533533
534534 Ok ( ( ) )
535535}
536+
537+ #[ test]
538+ fn secrets_outside_environment ( ) -> Result < ( ) > {
539+ insta:: assert_snapshot!(
540+ zizmor( )
541+ . input( input_under_test( "secrets-outside-environment.yml" ) )
542+ . run( ) ?
543+ ) ;
544+
545+ Ok ( ( ) )
546+ }
Original file line number Diff line number Diff line change 1- name : Action
21on : push
2+ permissions : {}
33jobs :
44 build :
5- name : Job
65 runs-on : ubuntu-latest
76 steps :
8- - name : Docker setup
9- uses : actions_repo/actions/docker@main
7+ - uses : actions_repo/actions/docker@main
108 with :
11- username : ${{ secrets.DOCKERHUB_USERNAME }}
9+ # NOT OK: Anyone with write access can exfiltrate this secret.
1210 password : ${{ secrets.DOCKERHUB_PASSWORD }}
You can’t perform that action at this time.
0 commit comments