samsmithnz / TurnBasedEngine

The logic for a turn-based game, to be consumed as a dependency in a Unity3d app (TBS)
MIT License
1 stars 0 forks source link

[Security] Workflow dotnet.yml is using vulnerable action gittools/actions/gitversion/execute #211

Closed Ale0x78 closed 1 year ago

Ale0x78 commented 2 years ago

The workflow dotnet.yml is referencing action gittools/actions/gitversion/execute using references v0.9.7. However this reference is missing the commit 90150b40fdd6c4b06d39cfd764e900cff45ccfca which may contain fix to the some vulnerability. The vulnerability fix that is missing by actions version could be related to: (1) CVE fix (2) upgrade of vulnerable dependency (3) fix to secret leak and others. Please consider to update the reference to the action.