You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
the repo is at the correct revision (git rev-parse head) is the same as the expected actions git sha
and that the checked out revision hasn't been modified (git status returns nothing)
Otherwise people might do something shady?
The text was updated successfully, but these errors were encountered:
I'm assuming we're talking about during attestation generation? If so then yeah the reusable workflow would be the trusted actor and if someone could mess with the checkout then they could just as easily mess with git or the output of git.
@zachariahcox notes:
We should check that:
Otherwise people might do something shady?
The text was updated successfully, but these errors were encountered: