github / github/accessibility-scanner

GitHub Script action not pinned to a full-length commit SHA

オープン
#169 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
369
フォーク
40
平均マージ
1日 9時間
マージ済み PR(30日)
10

説明

The `accessibility-scanner` workflow uses `actions/github-script@v8` without pinning it to a specific commit SHA. This violates security best practices and causes the pipeline to fail when the **Require actions to be pinned to a full-length commit SHA** setting is enabled.

#### **Steps to Reproduce**
1. Enable **Require actions to be pinned to a full-length commit SHA** in the repository settings.
2. Run the `accessibility-scanner` workflow.
3. Observe the failure caused by the unpinned `actions/github-script` action.

#### **Expected Behavior**
The workflow should run successfully with all actions pinned to full-length commit SHAs.

#### **Actual Behavior**
The workflow fails because `actions/github-script@v8` is not pinned to a commit SHA.

https://github.com/github/accessibility-scanner/blob/db51bb5d470a862cc027836ee1583ab9d5ae5b16/action.yml#L137

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。