Bump tabled from 0.20.0 to 0.21.0 #487
Annotations
10 errors, 11 warnings, and 1 notice
|
Show results in PR:
.github/workflows/make-release.yml#L42
make-release.yml:42: runtime artifacts potentially vulnerable to a cache poisoning attack: enables caching by default
|
|
Show results in PR:
.github/workflows/make-release.yml#L116
make-release.yml:116: code injection via template expansion: may expand into attacker-controllable code
|
|
Show results in PR:
.github/workflows/make-release.yml#L115
make-release.yml:115: code injection via template expansion: may expand into attacker-controllable code
|
|
Show results in PR:
.github/workflows/make-release.yml#L68
make-release.yml:68: code injection via template expansion: may expand into attacker-controllable code
|
|
Show results in PR:
.github/workflows/make-release.yml#L6
make-release.yml:6: overly broad permissions: contents: write is overly broad at the workflow level
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L45
generate-website-docs.yml:45: dangerous use of GitHub App tokens: app token inherits blanket installation permissions
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L51
generate-website-docs.yml:51: dangerous use of GitHub App tokens: token granted access to all repositories for this owner's app installation
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L33
generate-website-docs.yml:33: runtime artifacts potentially vulnerable to a cache poisoning attack: enables caching by default
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L28
generate-website-docs.yml:28: runtime artifacts potentially vulnerable to a cache poisoning attack: enables caching by default
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L23
generate-website-docs.yml:23: runtime artifacts potentially vulnerable to a cache poisoning attack: enables caching by default
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L14
generate-website-docs.yml:14: overly broad permissions: default permissions used due to no permissions: block
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L53
generate-website-docs.yml:53: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/generate-website-docs.yml#L19
generate-website-docs.yml:19: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/documentation-build.yml#L18
documentation-build.yml:18: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/cargo-test.yml#L26
cargo-test.yml:26: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/cargo-fmt.yml#L23
cargo-fmt.yml:23: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/cargo-clippy.yml#L15
cargo-clippy.yml:15: overly broad permissions: default permissions used due to no permissions: block
|
|
Show results in PR:
.github/workflows/cargo-clippy.yml#L19
cargo-clippy.yml:19: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Show results in PR:
.github/workflows/cargo-build-stable.yml#L22
cargo-build-stable.yml:22: overly broad permissions: default permissions used due to no permissions: block
|
|
Show results in PR:
.github/workflows/cargo-build-stable.yml#L26
cargo-build-stable.yml:26: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
Run KittyCAD/gha-workflows/.github/actions/zizmor-action@main
No file matched to [/home/runner/work/cli/cli/**/*requirements*.txt,/home/runner/work/cli/cli/**/*requirements*.in,/home/runner/work/cli/cli/**/*constraints*.txt,/home/runner/work/cli/cli/**/*constraints*.in,/home/runner/work/cli/cli/**/pyproject.toml,/home/runner/work/cli/cli/**/uv.lock,/home/runner/work/cli/cli/**/*.py.lock]. The cache will never get invalidated. Make sure you have checked out the target repository and configured the cache-dependency-glob input correctly.
|
|
Show results in PR:
.github/workflows/make-release.yml#L136
make-release.yml:136: action functionality is already included by the runner: use `gh release` in a script step
|
background
wait
wait-all
cancel
parallel
Loading