-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
FYI: Using the action like in the example would make you vulnerable to pwn requests #153
Comments
Thanks for opening your first issue here! Be sure to follow the issue template! |
@ST-DDT: This issue is currently awaiting triage. The triage/accepted label can be added by org members by writing /triage accepted in a comment. DetailsI am a bot created to help SwaragThaikkandi manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository. |
@ST-DDT: There are no 'kind' label on this PR. You need a 'kind' label to generate the release note automatically.
DetailsI am a bot created to help SwaragThaikkandi manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository. |
@ST-DDT: There are no area labels on this issue. Adding an appropriate label will greatly expedite the process for us. You can add as many area as you see fit. If you are unsure what to do you can ignore this!
DetailsI am a bot created to help SwaragThaikkandi manage community feedback and contributions. You can check out my manifest file to understand my behavior and what I can do. If you want to use this for your project, you can check out the BirthdayResearch/oss-governance-bot repository. |
/kind bug This isn't an actual security bug, but a potential for that. |
Hi, |
The current run-nothing example is safe, but running anything in there that uses the source code is dangerous as it uses elevated permissions.
I'll recommend rewriting/removing the example or raising awareness by adding a comment.
SMdRQA/.github/workflows/label.yml
Lines 27 to 28 in 6ed1aa9
SMdRQA/.github/workflows/label.yml
Lines 33 to 34 in 6ed1aa9
The text was updated successfully, but these errors were encountered: