makeplane / makeplane/plane

Action `actions/checkout` pinned to mutable ref `@v6`: `uses

Open
#9,108 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
59.6k
Forks
5.8k
Avg merge
1d 22h
Merged PRs (30d)
49

Description

Code-quality scan: makeplane/plane

Score: 71/100 (B) · 317 findings · scanned 2026-05-20 01:35 UTC · 404,320 LOC

Severity Count
CRITICAL 6
HIGH 111
MEDIUM 109
LOW 37

📊 Full filterable report · scorecard

Top findings
  1. HIGH MINED115 — Action actions/setup-python pinned to mutable ref @v6: uses .github/workflows/pull-request-build-lint-api.yml:32` · ✓ Repobility
  2. HIGH MINED115 — Action actions/checkout pinned to mutable ref @v6: uses .github/workflows/pull-request-build-lint-api.yml:30` · ✓ Repobility
  3. HIGH MINED115 — Action tailscale/github-action pinned to mutable ref @v4: uses .github/workflows/feature-deployment.yml:115` · ✓ Repobility
  4. HIGH MINED115 — Action actions/checkout pinned to mutable ref @v6: uses .github/workflows/feature-deployment.yml:79` · ✓ Repobility
  5. HIGH MINED115 — Action actions/checkout pinned to mutable ref @v6: uses .github/workflows/feature-deployment.yml:51` · ✓ Repobility

Filed automatically. Close this issue if not useful — we won't refile. Full report: https://repobility.com/scan/196b6a92-b6c5-45c0-91e9-a1a960a66add/

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the MINED115 findings in the linked report and inspect the referenced lines in .github/workflows/pull-request-build-lint-api.yml and .github/workflows/feature-deployment.yml. Review the repository's workflow action references, then rerun the scan or relevant CI checks to confirm the reported mutable-reference findings are resolved.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
64/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.