AdamMc331 / AdamMc331/AndroidStudyGuide

[Security] Workflow danger_checks.yml is using vulnerable action actions/checkout

未關閉
#83 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
Kotlin
星號
132
分支
8
PR 合併指標
30 天內沒有已合併 PR

描述

The workflow danger_checks.yml is referencing action actions/checkout using references v1. However this reference is missing the commit [a6747255bd19d7a757dbdda8c654a9f84db19839](https://github.com/actions/checkout/commits/a6747255bd19d7a757dbdda8c654a9f84db19839) which may contain fix to the some vulnerability.
The vulnerability fix that is missing by actions version could be related to:
(1) CVE fix
(2) upgrade of vulnerable dependency
(3) fix to secret leak and others.
Please consider to update the reference to the action.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。