Skip to content

OpenSSF: Dangerous-Workflow #231

Description

@kgiusti

The OpenSSF scorecard tool flagged the following workflow pattern as dangerous:

Warn: script injection with untrusted input 'github.event.comment.body': .github/workflows/greenboot-rs.yaml:53

Refer: https://github.com/ossf/scorecard/blob/main/docs/checks.md#dangerous-workflow

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions