carpentries / carpentries/actions

Audit actions for security

Open
#20 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
1
Forks
10
PR merge metrics
No merged PRs in 30d

Description

https://docs.github.com/en/actions/learn-github-actions/security-hardening-for-github-actions#understanding-the-risk-of-script-injections

Contributor guide

Open the contributing guide

Research direction

Start with the linked GitHub Actions security-hardening guidance, then inspect the repository's action workflows and JavaScript entry points for the risks it describes. The issue does not name files, tests, or completion criteria, so confirm the audit scope and what evidence of remediation is expected before starting.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, javascript
Domain
ci-cd, security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.