OpenAstronomy / OpenAstronomy/github-actions-workflows

SEC: several vulnerabilities detected with zizmor

Open
#364 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
21
Forks
27
Avg merge
2d 9h
Merged PRs (30d)
1

Description

This is a tracking issue

Since these workflows are widely used and even run automated package uploads (e.g. astropy-iers-data), it seems worth hardening their security as much as possible.

I intend to enable zizmor's pre-commit hook to continuously monitor vulnerabilities, but I need to fix existing ones first

linked PRs:

  • #363
  • #365
  • #366
  • #367
  • #368
  • #369
  • #370
  • #371
  • #373
  • #376
  • #377

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

This is a tracking issue for zizmor findings in reusable GitHub Actions workflows. Start by reviewing the listed PRs (#363, #365, #366, #367, #368, #369, #370, #371, #373, #376, and #377) and the affected workflow files. The work is done when the existing vulnerabilities are addressed and the zizmor pre-commit hook can monitor the workflows.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.