GnuComment: zizmor: ignore[dangerous-triggers]#6974
Conversation
|
GNU testsuite comparison: |
|
maybe it should be reported to upstream as a bug |
|
FWIW, this is not a false positive: the impact is low in your case, but any third-party fork can declare a new (In your case the attacker can run a workflow with upstream repo credentials, which they can then use to submit an arbitrary comment/contents as if it was your normal "testsuite comparison" response. This is pretty low-impact, but it's probably not something you intended 🙂) |
|
Thanks for the information! If we were going to fix this what would we do? |
|
My recommendation would be to switch from |
This looks like a false positive.