Repository navigation
ci(deps): Bump the actions group across 1 directory with 3 updates #13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -25,8 +25,8 @@ jobs: | |
| run: | ||
| working-directory: ansible | ||
| steps: | ||
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 | ||
| - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 | ||
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | ||
|
Comment on lines
+28
to
+29
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Show the workflow around the referenced lines with numbers.
sed -n '1,120p' .github/workflows/molecule.yml | cat -nRepository: decdn/devops Length of output: 1562 🏁 Script executed: #!/bin/bash
set -euo pipefail
# Check whether the Molecule job or Ansible test setup depends on git credentials or submodules.
rg -n --hidden --glob '!**/.git/**' \
-e 'submodule' -e 'git ' -e 'github.token' -e 'GITHUB_TOKEN' -e 'persist-credentials' \
.github ansibleRepository: decdn/devops Length of output: 257 Disable persisted credentials on checkout. This job only runs Molecule tests, so the GitHub token does not need to remain in git config. Set 🧰 Tools🪛 zizmor (1.26.1)[warning] 28-28: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
| with: | ||
| python-version: '3.12' | ||
| - name: Install molecule + Ansible | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: decdn/devops
Length of output: 8141
Disable persisted credentials on each checkout step.
.github/workflows/ci.yml:30,48,80,120,155These jobs only lint/build/scan and never need repo auth, so addpersist-credentials: falseto everyactions/checkoutinvocation to keep the token out of.git/config.🧰 Tools
🪛 zizmor (1.26.1)
[warning] 30-30: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
🤖 Prompt for AI Agents
Source: Linters/SAST tools