Security audit of templated workflows
- Dominant language
- Python
- Stars
- 3
- Forks
- 7
- Avg merge
- 3d 21h
- Merged PRs (30d)
- 12
Description
### Checklist
- [x] I added a descriptive title
- [x] I searched open reports and couldn't find a duplicate
### What happened?
I have zizmor GHA vuln scanning enabled on conda-lock. Not that it makes security perfect, but I use it to help enforce standards to make obvious vulnerabilities less likely.
I was getting several warnings from the current templated workflows which I fixed in https://github.com/conda/conda-lock/pull/814. However, now the updates want to overwrite my changes, so I think we should consider upstreaming these changes. What do you think?
### Additional Context
_No response_
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by inspecting the repository's templated workflows and compare them with the security-related changes in conda-lock PR 814. Run the zizmor scan or the repository's existing checks to identify the current warnings. Done means the upstream templates include the needed security changes and no longer overwrite those fixes in generated workflows.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, devops, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100