[POC - do not merge] TT-18139: release pipelines as reusable workflows #37
Annotations
10 errors, 12 warnings, and 10 notices
|
template-injection:
.github/actions/tests/choose-test-branch/action.yaml#L32
action.yaml:32: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/tests/choose-test-branch/action.yaml#L31
action.yaml:31: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/tests/api-tests/action.yaml#L47
action.yaml:47: code injection via template expansion: may expand into attacker-controllable code
|
|
github-env:
.github/actions/latest-versions/action.yaml#L38
action.yaml:38: dangerous use of environment file: write to GITHUB_PATH may allow code execution
|
|
template-injection:
.github/actions/latest-versions/action.yaml#L44
action.yaml:44: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/latest-versions/action.yaml#L44
action.yaml:44: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/latest-versions/action.yaml#L44
action.yaml:44: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/latest-versions/action.yaml#L44
action.yaml:44: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/actions/latest-versions/action.yaml#L44
action.yaml:44: code injection via template expansion: may expand into attacker-controllable code
|
|
github-env:
.github/actions/checkout-pr/action.yml#L19
action.yml:19: dangerous use of environment file: write to GITHUB_ENV may allow code execution
|
|
zizmor / scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
ref-version-mismatch:
.github/workflows/branch-suggestion.yml#L26
branch-suggestion.yml:26: action's hash pin has mismatched or missing version comment: points to commit 11d5960a3267
|
|
artipacked:
.github/workflows/branch-suggestion.yml#L28
branch-suggestion.yml:28: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
artipacked:
.github/workflows/branch-suggestion.yml#L24
branch-suggestion.yml:24: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
ref-version-mismatch:
.github/actions/tests/choose-test-branch/action.yaml#L17
action.yaml:17: action's hash pin has mismatched or missing version comment: points to commit 11d5960a3267
|
|
artipacked:
.github/actions/tests/choose-test-branch/action.yaml#L17
action.yaml:17: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
ref-version-mismatch:
.github/actions/ecr-login/action.yml#L22
action.yml:22: action's hash pin has mismatched or missing version comment: points to commit 03f1aad4c6c7
|
|
ref-version-mismatch:
.github/actions/ecr-login/action.yml#L15
action.yml:15: action's hash pin has mismatched or missing version comment: points to commit 7474bc4690e2
|
|
ref-version-mismatch:
.github/actions/checkout-pr/action.yml#L22
action.yml:22: action's hash pin has mismatched or missing version comment: points to commit 11d5960a3267
|
|
template-injection:
.github/actions/checkout-pr/action.yml#L45
action.yml:45: code injection via template expansion: may expand into attacker-controllable code
|
|
artipacked:
.github/actions/checkout-pr/action.yml#L21
action.yml:21: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
zizmor / scan
No file matched to [/home/runner/work/github-actions/github-actions/**/*requirements*.txt,/home/runner/work/github-actions/github-actions/**/*requirements*.in,/home/runner/work/github-actions/github-actions/**/*constraints*.txt,/home/runner/work/github-actions/github-actions/**/*constraints*.in,/home/runner/work/github-actions/github-actions/**/pyproject.toml,/home/runner/work/github-actions/github-actions/**/uv.lock,/home/runner/work/github-actions/github-actions/**/*.py.lock]. The cache will never get invalidated. Make sure you have checked out the target repository and configured the cache-dependency-glob input correctly.
|
|
template-injection:
.github/workflows/release-tyk-analytics.yml#L463
release-tyk-analytics.yml:463: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-tyk-analytics.yml#L383
release-tyk-analytics.yml:383: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-tyk-analytics.yml#L306
release-tyk-analytics.yml:306: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-tyk-analytics.yml#L206
release-tyk-analytics.yml:206: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L348
release-bot.yaml:348: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L340
release-bot.yaml:340: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L338
release-bot.yaml:338: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L337
release-bot.yaml:337: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L145
release-bot.yaml:145: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/release-bot.yaml#L120
release-bot.yaml:120: code injection via template expansion: may expand into attacker-controllable code
|