-
Notifications
You must be signed in to change notification settings - Fork 0
Use of non-approved third-party GitHub Actions #29
Copy link
Copy link
Open
Description
Use of non-approved third-party GitHub Actions
Some GitHub Actions workflows in outline-cli repository use third-party actions that fall outside our approved tiers:
According to our GitHub Actions handbook, we only allow:
- Tier 1: Actions from trusted organizations (GitHub, AWS, Google, etc.)
- Tier 2: Audited actions pinned to specific commit SHAs
Required action:
Choose one of these options:
- Replace with an approved alternative or custom script
- Audit the action's code and add it to Tier 2 (pinned to full SHA)
- Discuss in #Doist Dev if you believe the author should be added to Tier 1
See the handbook for detailed guidance on each option.
(Relates to https://github.com/Doist/platform-backlog/issues/983)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels