carpentries / carpentries/actions
Audit actions for security
Open
- Dominant language
- JavaScript
- Stars
- 1
- Forks
- 10
- PR merge metrics
- No merged PRs in 30d
Description
https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections
Contributor guide
Research direction
Start with the linked GitHub Actions security-hardening guidance, then inspect the repository's action workflows and JavaScript entry points for the risks it describes. The issue does not name files, tests, or completion criteria, so confirm the audit scope and what evidence of remediation is expected before starting.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions, javascript
- Domain
- ci-cd, security
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100