You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I was browsing to the GitHub Advisory Database for the GitHub Actions ecosystem (looking for potential additions to the ADES2XX rules) and noticed some vulnerabilities that would have been avoided by using this project. For now I'll keep a list here but at some point maybe it makes sense to add it to the documentation.
Where Relevant means the vulnerability is caused by the use of workflow expressions and -conservative indicates if the problem would be found by ades when using the -conservative flag.
The text was updated successfully, but these errors were encountered:
Summary
I was browsing to the GitHub Advisory Database for the GitHub Actions ecosystem (looking for potential additions to the ADES2XX rules) and noticed some vulnerabilities that would have been avoided by using this project. For now I'll keep a list here but at some point maybe it makes sense to add it to the documentation.
From new to old:
-conservative
Where Relevant means the vulnerability is caused by the use of workflow expressions and
-conservative
indicates if the problem would be found byades
when using the-conservative
flag.The text was updated successfully, but these errors were encountered: