-
Notifications
You must be signed in to change notification settings - Fork 38
validate-project action is too strict on security advisory URL #671
Copy link
Copy link
Open
Labels
area/dot-projectutilities/dot-project scaffolding and bootstrap toolingutilities/dot-project scaffolding and bootstrap toolingneeds-groupIndicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)Indicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-priorityIndicates an issue or PR missing a priority labelIndicates an issue or PR missing a priority labelneeds-statusIndicates an issue or PR missing a status labelIndicates an issue or PR missing a status labelneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)
Description
Activity
Metadata
Metadata
Assignees
Labels
area/dot-projectutilities/dot-project scaffolding and bootstrap toolingutilities/dot-project scaffolding and bootstrap toolingneeds-groupIndicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied)needs-kindIndicates an issue or PR that is missing an issue type or kind (a kind/foo label)Indicates an issue or PR that is missing an issue type or kind (a kind/foo label)needs-priorityIndicates an issue or PR missing a priority labelIndicates an issue or PR missing a priority labelneeds-statusIndicates an issue or PR missing a status labelIndicates an issue or PR missing a status labelneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)
The validator requires a GHSA report URL.
For projects like Argo with multiple subprojects, there's no single GHSA report link.
Example failure: https://github.com/argoproj/.project/actions/runs/34403020101/job/102639227931?pr=4