Skip to content

Use of non-approved third-party GitHub Actions #29

@scan-github-workflows

Description

@scan-github-workflows

Use of non-approved third-party GitHub Actions

Some GitHub Actions workflows in outline-cli repository use third-party actions that fall outside our approved tiers:

According to our GitHub Actions handbook, we only allow:

  • Tier 1: Actions from trusted organizations (GitHub, AWS, Google, etc.)
  • Tier 2: Audited actions pinned to specific commit SHAs

Required action:

Choose one of these options:

  1. Replace with an approved alternative or custom script
  2. Audit the action's code and add it to Tier 2 (pinned to full SHA)
  3. Discuss in #Doist Dev if you believe the author should be added to Tier 1

See the handbook for detailed guidance on each option.

(Relates to https://github.com/Doist/platform-backlog/issues/983)

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions