Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Composite actions: support for existing audits #350

Open
12 of 14 tasks
woodruffw opened this issue Dec 23, 2024 · 4 comments
Open
12 of 14 tasks

Composite actions: support for existing audits #350

woodruffw opened this issue Dec 23, 2024 · 4 comments
Labels
enhancement New feature or request help wanted Extra attention is needed

Comments

@woodruffw
Copy link
Owner

woodruffw commented Dec 23, 2024

#331 will add composite action support. From there, the current audits need to be extended to work with composite actions, where appropriate.

@woodruffw woodruffw added the enhancement New feature or request label Dec 23, 2024
@woodruffw woodruffw self-assigned this Dec 23, 2024
@woodruffw woodruffw removed their assignment Dec 25, 2024
@woodruffw woodruffw added the help wanted Extra attention is needed label Dec 25, 2024
@woodruffw
Copy link
Owner Author

I'm going to keep burning this down, but I would appreciate help as well! If anybody is interested in working on one of these, leave a comment here and I'll assign it to you 🙂

@ubiratansoares
Copy link
Contributor

ubiratansoares commented Dec 26, 2024

@woodruffw Happy to help here!

Let me give a try on known-vulnerable-actions, unpinned-uses, and ref-confusion, they don't look too hard and I can learn a bit more about their inner details along the way. I'll raise individual PRs for each one, for the sake of easier reviews 🙂

@ubiratansoares
Copy link
Contributor

@woodruffw Happy new year 🎉🎉🎉

If ok for you, I'm happy take the 2 remaining audits, so we get the all audits supported in Composite Actions 🙂

@woodruffw
Copy link
Owner Author

That would be awesome, thank you @ubiratansoares! And happy new year!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request help wanted Extra attention is needed
Projects
None yet
Development

No branches or pull requests

2 participants