Skip to content

BUILD-7998: Security audit fixes#331

Merged
jayadeep-km-sonarsource merged 1 commit intomasterfrom
feat/jd/BUILD-7998-security-fixes
Jul 31, 2025
Merged

BUILD-7998: Security audit fixes#331
jayadeep-km-sonarsource merged 1 commit intomasterfrom
feat/jd/BUILD-7998-security-fixes

Conversation

@jayadeep-km-sonarsource
Copy link
Copy Markdown
Contributor

@jayadeep-km-sonarsource jayadeep-km-sonarsource commented Jul 29, 2025

BUILD-7998: Security audit fixes (details in the ticket)

@jayadeep-km-sonarsource jayadeep-km-sonarsource force-pushed the feat/jd/BUILD-7998-security-fixes branch from c582087 to ff273e0 Compare July 29, 2025 09:40
Signed-off-by: Jayadeep Kinavoor Madam <jayadeep.kinavoormadam@sonarsource.com>
@jayadeep-km-sonarsource jayadeep-km-sonarsource force-pushed the feat/jd/BUILD-7998-security-fixes branch from ff273e0 to 2517d02 Compare July 30, 2025 14:55
@sonarqubecloud
Copy link
Copy Markdown

🤖 Pull Request summary

Update GitHub Actions security and configuration.

• Pin SonarCloud action to specific commit hash (v5.0.0) instead of using @master
• Remove documentation exclusion from CODEOWNERS file requiring all changes to be reviewed
• Add explanatory comments for workflow permissions in it-test.yml
• Refactor release.yml to use environment variables instead of inline parameters
• Enhance download-build action with input sanitization to prevent environment variable injection

💬 Please send your feedback

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarQube Cloud

@jayadeep-km-sonarsource jayadeep-km-sonarsource marked this pull request as ready for review July 30, 2025 16:00
@jayadeep-km-sonarsource jayadeep-km-sonarsource requested a review from a team as a code owner July 30, 2025 16:00
@jayadeep-km-sonarsource jayadeep-km-sonarsource enabled auto-merge (squash) July 30, 2025 16:01
@SamirM-BE SamirM-BE disabled auto-merge July 31, 2025 06:46
@jayadeep-km-sonarsource jayadeep-km-sonarsource merged commit 6b7ef06 into master Jul 31, 2025
15 checks passed
@jayadeep-km-sonarsource jayadeep-km-sonarsource deleted the feat/jd/BUILD-7998-security-fixes branch July 31, 2025 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants