Sitelet https://github.com/taiki-e/install-action/issues/1631
Skip to content

Detect and maybe reject support of tools that having obviously dangerous workflows #1631

Description

@taiki-e

I'd like to establish a criterion for accepting or rejecting tool support that requires them not to use obviously dangerous workflows.

I don’t think it’s necessary to satisfy all of zizmor’s lint rules, but if triggers like https://docs.zizmor.sh/audits/#dangerous-triggers or comments-related are existed or added later (i.e., manual reviews when adding tools don’t work), I’d like to be able to reject the addition of tool support or version updates.

Related: #488
Unlike that case, since the maintainer lacks awareness of GHA security but has no malicious intent, I don’t think this situation is as difficult as that one.

However, we should avoid using support for this action as an excuse to submit reports that have nothing to do with actual vulnerabilities like rust-lang/rust#154414, thus burdening the maintainer.

cc @jayvdb

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions