Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

use zizmor to static analysis the GitHub Actions files and fix them #5281

Open
yihong0618 opened this issue Jan 3, 2025 · 2 comments
Open
Labels
C-enhancement Category Enhancements

Comments

@yihong0618
Copy link
Contributor

yihong0618 commented Jan 3, 2025

What type of enhancement is this?

Other

What does the enhancement do?

As more and more attackers using GitHub Actions to steal the token or attack other users such as Mining Scripts

zizmor: https://woodruffw.github.io/zizmor/

more can check issue one-api or https://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/
we can use static check to avoid them as we can.

same request for opendal apache/opendal#5502

Implementation challenges

No response

@yihong0618 yihong0618 added the C-enhancement Category Enhancements label Jan 3, 2025
@killme2008
Copy link
Contributor

@yihong0618 Interesting!

@sunng87 What do you think?

@sunng87
Copy link
Member

sunng87 commented Jan 8, 2025

Pull request is welcomed. We can add a check only when workflow yamls are modified.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
C-enhancement Category Enhancements
Projects
None yet
Development

No branches or pull requests

3 participants