POC Option 1B: Specialized REST Upload Stub #2971
github_actions_scan.yml Required
on: pull_request_target
check-changes
2m 47s
zizmor-output
1m 17s
zizmor-upload
7s
Annotations
20 errors and 12 warnings
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L99
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L97
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L77
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L70
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L68
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/ci.yaml#L35
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/template-injection:
.github/workflows/ci.yaml#L423
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor/unpinned-uses:
.github/workflows/changelog_generation_test.yaml#L14
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/changelog_generation.yaml#L26
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor-output
Found 294 findings for mandatory checks that must always succeed.
|
|
unpinned-uses:
.github/workflows/ci.yaml#L110
ci.yaml:110: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L99
ci.yaml:99: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L97
ci.yaml:97: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L77
ci.yaml:77: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L70
ci.yaml:70: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L68
ci.yaml:68: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/ci.yaml#L35
ci.yaml:35: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
template-injection:
.github/workflows/ci.yaml#L423
ci.yaml:423: code injection via template expansion: may expand into attacker-controllable code
|
|
unpinned-uses:
.github/workflows/changelog_generation_test.yaml#L14
changelog_generation_test.yaml:14: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/changelog_generation.yaml#L26
changelog_generation.yaml:26: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor-config
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
zizmor-upload
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
excessive-permissions:
.github/workflows/ci.yaml#L312
ci.yaml:312: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L295
ci.yaml:295: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L244
ci.yaml:244: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L222
ci.yaml:222: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L88
ci.yaml:88: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L56
ci.yaml:56: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/ci.yaml#L16
ci.yaml:16: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/changelog_generation_test.yaml#L10
changelog_generation_test.yaml:10: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/changelog_generation.yaml#L9
changelog_generation.yaml:9: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/changelog_generation.yaml#L1
changelog_generation.yaml:1: overly broad permissions: default permissions used due to no permissions: block
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
zizmor
Expired
|
123 KB |
sha256:be98b8b4f0796915bd91f49e89f983a3815e219e2340ae25b2a4d0007ce442e6
|
|
|
zizmor-config
Expired
|
342 Bytes |
sha256:4fd9c1a60cfe5402a066d673a10669ab33951895481fa72aa54614a0b362ec98
|
|