Skip to content

Conversation

@woodruffw
Copy link
Member

See zizmorcore/github-actions-models#21.

There are certainly other places where the env: can be non-static, but this gets us started.

The only place where this currently affects zizmor is in the insecure-commands audit -- I've refactored it so that a non-static env: produces an "auditor" persona finding.

CC @ubiratansoares for viz, since you wrote this audit 🙂

@woodruffw woodruffw added the bugfix Fixes a known bug label Dec 8, 2024
@woodruffw woodruffw self-assigned this Dec 8, 2024
@woodruffw woodruffw enabled auto-merge (squash) December 8, 2024 01:10
@woodruffw woodruffw merged commit e50f954 into main Dec 8, 2024
17 checks passed
@woodruffw woodruffw deleted the ww/bump-models branch December 8, 2024 01:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes a known bug

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants