Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: Apply CodeQL workflow fixes #1319

Draft
wants to merge 4 commits into
base: main
Choose a base branch
from

use latest Ruby setup

7fb2335
Select commit
Loading
Failed to load commit list.
Draft

ci: Apply CodeQL workflow fixes #1319

use latest Ruby setup
7fb2335
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Jan 15, 2025 in 5s

8 new alerts including 8 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 8 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 34 in .github/workflows/deploy-website.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Deploy website' step
Uses Step
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash

Check warning on line 66 in .github/workflows/deploy-website.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Deploy website' step
Uses Step: deploy
uses 'cloudflare/wrangler-action' with ref 'v3.1.0', not a pinned commit hash

Check warning on line 19 in .github/workflows/lint-pull-request.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Pull request' step
Uses Step: lint_pr_title
uses 'amannn/action-semantic-pull-request' with ref 'v5.1.0', not a pinned commit hash

Check warning on line 32 in .github/workflows/lint-pull-request.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Pull request' step
Uses Step
uses 'marocchino/sticky-pull-request-comment' with ref 'v2.1.0', not a pinned commit hash

Check warning on line 81 in .github/workflows/lint-pull-request.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Pull request' step
Uses Step
uses 'marocchino/sticky-pull-request-comment' with ref 'v2.1.0', not a pinned commit hash

Check warning on line 22 in .github/workflows/lock-issues-pr.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Lock closed threads' step
Uses Step
uses 'dessant/lock-threads' with ref 'v5.0.1', not a pinned commit hash

Check warning on line 33 in .github/workflows/test-website-a11y.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium test

Unpinned 3rd party Action 'Website a11y' step
Uses Step
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash

Check warning on line 33 in .github/workflows/test-website-links.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium test

Unpinned 3rd party Action 'Website URLs' step
Uses Step
uses 'ruby/setup-ruby' with ref 'v1.207.0', not a pinned commit hash