Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

new feature: use zizmor to static analysis the GitHub Actions files and fix them #5502

Open
1 task
yihong0618 opened this issue Jan 3, 2025 · 0 comments
Open
1 task
Labels
enhancement New feature or request

Comments

@yihong0618
Copy link
Contributor

yihong0618 commented Jan 3, 2025

Feature Description

zizmor: https://woodruffw.github.io/zizmor/

As more and more attackers using GitHub Actions to steal the token or attack other users such as Mining Scripts
more can check issue one-api or https://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/
we can use static check to avoid them as we can.

Problem and Solution

using zizmor to fix all

Additional Context

No response

Are you willing to contribute to the development of this feature?

  • Yes, I am willing to contribute to the development of this feature.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant