conda / conda/actions

Security audit of templated workflows

Open
#314 1 comment 0 reactions 0 assignees View on GitHub
stale type::bug
Dominant language
Python
Stars
3
Forks
7
Avg merge
3d 21h
Merged PRs (30d)
12

Description

### Checklist

- [x] I added a descriptive title
- [x] I searched open reports and couldn't find a duplicate

### What happened?

I have zizmor GHA vuln scanning enabled on conda-lock. Not that it makes security perfect, but I use it to help enforce standards to make obvious vulnerabilities less likely.

I was getting several warnings from the current templated workflows which I fixed in https://github.com/conda/conda-lock/pull/814. However, now the updates want to overwrite my changes, so I think we should consider upstreaming these changes. What do you think?

### Additional Context

_No response_

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by inspecting the repository's templated workflows and compare them with the security-related changes in conda-lock PR 814. Run the zizmor scan or the repository's existing checks to identify the current warnings. Done means the upstream templates include the needed security changes and no longer overwrite those fixes in generated workflows.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, devops, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.