This issue was automatically created by Allstar.
Security Policy Violation
Project is out of compliance with Dangerous Workflow policy: dangerous workflow patterns detected
**Rule Description**
Dangerous workflows are GitHub Action workflows that exhibit dangerous patterns that could render them vulnerable to attack. A vulnerable workflow is susceptible to leaking repository secrets, or allowing an attacker write access using the GITHUB_TOKEN. For more information about the particular patterns that are detected, see the [OpenSSF Scorecard documentation](https://github.com/ossf/scorecard/blob/main/docs/checks.md#dangerous-workflow) on dangerous workflows. Any vulnerable branch can be exploited, so this rule will check all branches (vulnerable list below).
**Remediation Steps**
Avoid the dangerous workflow patterns. See this [post](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/) for information on avoiding untrusted code checkouts. See this [document](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#understanding-the-risk-of-script-injections) for information on avoiding and mitigating the risk of script injections.
**Dangerous Patterns Found**
Additional Information
This policy uses OpenSSF Scorecard. You may wish to run a Scorecard scan directly on this repository for more details.
Vulnerable Branch: refs/remotes/origin/copilot/sub-pr-118
Vulnerable Branch: refs/remotes/origin/copilot/sub-pr-118-again
Vulnerable Branch: refs/remotes/origin/fix-cert-return-type
Vulnerable Branch: refs/remotes/origin/main
Vulnerable Branch: refs/remotes/origin/renovate/actions-cache-5.x
Vulnerable Branch: refs/remotes/origin/renovate/actions-checkout-6.x
Vulnerable Branch: refs/remotes/origin/renovate/actions-setup-java-5.x
Vulnerable Branch: refs/remotes/origin/renovate/aquasecurity-trivy-action-0.x
Vulnerable Branch: refs/remotes/origin/renovate/major-version.testcontainers.keycloak
Vulnerable Branch: refs/remotes/origin/renovate/version.jjwt
Vulnerable Branch: refs/remotes/origin/renovate/version.postgresql
This issue will auto resolve when the policy is in compliance.
Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.
This issue was automatically created by Allstar.
Security Policy Violation
Project is out of compliance with Dangerous Workflow policy: dangerous workflow patterns detected
Additional Information
This policy uses OpenSSF Scorecard. You may wish to run a Scorecard scan directly on this repository for more details.
Vulnerable Branch: refs/remotes/origin/copilot/sub-pr-118
Vulnerable Branch: refs/remotes/origin/copilot/sub-pr-118-again
Vulnerable Branch: refs/remotes/origin/fix-cert-return-type
Vulnerable Branch: refs/remotes/origin/main
Vulnerable Branch: refs/remotes/origin/renovate/actions-cache-5.x
Vulnerable Branch: refs/remotes/origin/renovate/actions-checkout-6.x
Vulnerable Branch: refs/remotes/origin/renovate/actions-setup-java-5.x
Vulnerable Branch: refs/remotes/origin/renovate/aquasecurity-trivy-action-0.x
Vulnerable Branch: refs/remotes/origin/renovate/major-version.testcontainers.keycloak
Vulnerable Branch: refs/remotes/origin/renovate/version.jjwt
Vulnerable Branch: refs/remotes/origin/renovate/version.postgresql
This issue will auto resolve when the policy is in compliance.
Issue created by Allstar. See https://github.com/ossf/allstar/ for more information. For questions specific to the repository, please contact the owner or maintainer.