Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Release V2.1.0 #276

Merged
merged 34 commits into from
Dec 3, 2024

ci: sync workflows from central-workflows (#201)

4bfbcb4
Select commit
Loading
Failed to load commit list.
Merged

feat: Release V2.1.0 #276

ci: sync workflows from central-workflows (#201)
4bfbcb4
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Scorecard failed Dec 3, 2024 in 2s

22 new alerts including 2 critical severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 critical
  • 5 high
  • 15 medium

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1 in .github/workflows/bench.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 64 in .github/workflows/codacy.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 1 in .github/workflows/codeql.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 53 in .github/workflows/codeql.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 67 in .github/workflows/codeql.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 80 in .github/workflows/codeql.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 1 in .github/workflows/dco-check.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 20 in .github/workflows/dco-check.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 25 in .github/workflows/dco-check.yml

See this annotation in the file changed.

Code scanning / Scorecard

Dangerous-Workflow Critical

score is 0: script injection with untrusted input ' github.event.pull_request.head.ref '
Click Remediation section below to solve this issue

Check warning on line 26 in .github/workflows/dependency-review.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 38 in .github/workflows/dockerfile-linter.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 49 in .github/workflows/dockerfile-linter.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 1 in .github/workflows/dockerhub-image-build.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 32 in .github/workflows/dockerhub-image-build.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 68 in .github/workflows/dockerhub-image-build.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 21 in .github/workflows/gpg-verify.yml

See this annotation in the file changed.

Code scanning / Scorecard

Dangerous-Workflow Critical

score is 0: script injection with untrusted input ' github.event.pull_request.head.ref '
Click Remediation section below to solve this issue

Check failure on line 1 in .github/workflows/milestone.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 45 in .github/workflows/njsscan.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 48 in .github/workflows/release.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: third-party GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 216 in .github/workflows/release.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check failure on line 1 in .github/workflows/terraform-security.yml

See this annotation in the file changed.

Code scanning / Scorecard

Token-Permissions High

score is 0: no topLevel permission defined
Remediation tip: Visit https://app.stepsecurity.io/secureworkflow.
Tick the 'Restrict permissions for GITHUB_TOKEN'
Untick other options
NOTE: If you want to resolve multiple issues at once, you can visit https://app.stepsecurity.io/securerepo instead.
Click Remediation section below for further remediation help

Check warning on line 29 in .github/workflows/terraform-security.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help

Check warning on line 37 in .github/workflows/terraform-security.yml

See this annotation in the file changed.

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 4: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help