Update workflows with agent marketplace generation files #6
Triggered via pull request
August 3, 2026 10:51
simona-anomis
opened
#124
Status
Failure
Total duration
56s
Artifacts
2
github_actions_scan.yml Required
on: pull_request_target
Annotations
16 errors and 2 warnings
|
zizmor-output
Process completed with exit code 1.
|
|
zizmor/unpinned-uses:
.github/workflows/update-skills.yml#L17
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/unpinned-uses:
.github/workflows/create-release.yml#L19
unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
zizmor/template-injection:
.github/workflows/create-release.yml#L61
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor/template-injection:
.github/workflows/create-release.yml#L60
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor/template-injection:
.github/workflows/create-release.yml#L58
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor/template-injection:
.github/workflows/create-release.yml#L47
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor/template-injection:
.github/workflows/create-release.yml#L26
code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor-output
Found 7 findings for mandatory checks that must always succeed.
|
|
unpinned-uses:
.github/workflows/update-skills.yml#L17
update-skills.yml:17: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
unpinned-uses:
.github/workflows/create-release.yml#L19
create-release.yml:19: unpinned action reference: action is not pinned to a hash (required by blanket policy)
|
|
template-injection:
.github/workflows/create-release.yml#L61
create-release.yml:61: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/create-release.yml#L60
create-release.yml:60: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/create-release.yml#L58
create-release.yml:58: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/create-release.yml#L47
create-release.yml:47: code injection via template expansion: may expand into attacker-controllable code
|
|
template-injection:
.github/workflows/create-release.yml#L26
create-release.yml:26: code injection via template expansion: may expand into attacker-controllable code
|
|
zizmor-config
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
zizmor-upload
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
zizmor
Expired
|
3.57 KB |
sha256:72252b58d2b954e08cdfabf8abe19de0ee884289c6e96d586785e40bbf310a8b
|
|
|
zizmor-config
Expired
|
295 Bytes |
sha256:ac753db621b8dae57bc6cbc80d23c173c50706d1047baaef607520751749bdd9
|
|