entooone / freestylewiki-vscode

FreeStyleWiki 用の Visual Studio Code 拡張機能
Apache License 2.0
6 stars 0 forks source link

[Security] Workflow reviewdog.yml is using vulnerable action reviewdog/action-eslint #19

Closed fockboi-lgtm closed 2 years ago

fockboi-lgtm commented 2 years ago

The workflow reviewdog.yml is referencing action reviewdog/action-eslint using references v1. However this reference is missing the commit 7b45345d875d4979afe88b630dbc01a40e8a2e91 which may contain fix to the some vulnerability. The vulnerability fix that is missing by actions version could be related to: (1) CVE fix (2) upgrade of vulnerable dependency (3) fix to secret leak and others. Please consider to update the reference to the action.

entooone commented 2 years ago

Thank you, I fixed it.