Test zizmor scanner findings - #38
7 new alerts including 3 errors
New alerts in code changed by this pull request
- 3 errors
- 1 warning
- 3 notes
See annotations below for details.
Annotations
Check failure on line 7 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
overly broad permissions: contents: write is overly broad at the workflow level Error
Check failure on line 14 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
unpinned action reference: action is not pinned to a hash (required by blanket policy) Error
Check failure on line 17 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
code injection via template expansion: may expand into attacker-controllable code Error
Check warning on line 14 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
credential persistence through GitHub Actions artifacts: does not set persist-credentials: false Warning
Check notice on line 4 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
insufficient job-level concurrency limits: workflow is missing concurrency setting Note
Check notice on line 7 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
permissions without explanatory comments: needs an explanatory comment Note
Check notice on line 10 in .github/workflows/zizmor-test.yml
Code scanning / zizmor
workflow or action definition without a name: this job Note