Closed coroiu closed 1 month ago
Checkmarx One – Scan Summary & Details – 8b692432-425e-49ab-aaa3-18bd724d98f8
Severity | Issue | Source File / Package | Checkmarx Insight |
---|---|---|---|
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 61 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-python.yml: 108 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /version-bump.yml: 54 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 54 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 163 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 44 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-napi.yml: 111 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-swift.yml: 96 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 173 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 86 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-rust-crates.yml: 77 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 131 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-wasm.yml: 87 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 169 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 338 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 93 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 52 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-wasm.yml: 87 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 163 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 86 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 173 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 54 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 131 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /version-bump.yml: 54 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-swift.yml: 96 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 169 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-rust-crates.yml: 77 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-python.yml: 108 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 61 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 44 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 338 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 52 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 93 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... | |
Unpinned Actions Full Length Commit SHA | /publish-napi.yml: 111 | Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps... |
Severity | Issue | Source File / Package |
---|---|---|
Unpinned Actions Full Length Commit SHA | /publish-rust-crates.yml: 76 | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 43 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 85 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 337 | |
Unpinned Actions Full Length Commit SHA | /publish-python.yml: 107 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 60 | |
Unpinned Actions Full Length Commit SHA | /publish-wasm.yml: 86 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 162 | |
Unpinned Actions Full Length Commit SHA | /version-bump.yml: 53 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 53 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 92 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 172 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 168 | |
Unpinned Actions Full Length Commit SHA | /build-swift.yml: 95 | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 51 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 130 | |
Unpinned Actions Full Length Commit SHA | /publish-napi.yml: 110 | |
Unpinned Actions Full Length Commit SHA | /publish-rust-crates.yml: 76 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 85 | |
Unpinned Actions Full Length Commit SHA | /publish-napi.yml: 110 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 172 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 92 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 162 | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 43 | |
Unpinned Actions Full Length Commit SHA | /publish-bws.yml: 168 | |
Unpinned Actions Full Length Commit SHA | /release-bws.yml: 51 | |
Unpinned Actions Full Length Commit SHA | /build-cli.yml: 337 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 130 | |
Unpinned Actions Full Length Commit SHA | /build-swift.yml: 95 | |
Unpinned Actions Full Length Commit SHA | /publish-wasm.yml: 86 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 60 | |
Unpinned Actions Full Length Commit SHA | /build-cli-docker.yml: 53 | |
Unpinned Actions Full Length Commit SHA | /publish-python.yml: 107 |
All modified and coverable lines are covered by tests :white_check_mark:
Project coverage is 58.15%. Comparing base (
6460db2
) to head (f7fdeb5
). Report is 2 commits behind head on main.
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
🎟️ Tracking
📔 Objective
⏰ Reminders before review
🦮 Reviewer guidelines
:+1:
) or similar for great changes:memo:
) or ℹ️ (:information_source:
) for notes or general info:question:
) for questions:thinking:
) or 💭 (:thought_balloon:
) for more open inquiry that's not quite a confirmed issue and could potentially benefit from discussion:art:
) for suggestions / improvements:x:
) or ⚠️ (:warning:
) for more significant problems or concerns needing attention:seedling:
) or ♻️ (:recycle:
) for future improvements or indications of technical debt:pick:
) for minor or nitpick changes