+
Skip to content

feat: new audit: anonymous-definition #937

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged

Conversation

andrewpollack
Copy link
Contributor

Notes:

  • GitHub UI being impacted by unnamed Workflows make severity feel higher for that than jobs. That said, since it is not a security problem, I felt like "Low" was appropriate. Curious thoughts on this.
  • I left out 'ReusableWorkflowCallJob' since as far as I could tell, they did not have any naming capabilities

Closes: #795

Notes:
* GitHub UI being impacted by unnamed Workflows make severity feel higher for that than
  jobs. That said, since it is not a security problem, I felt like "Low" was appropriate.
  Curious thoughts on this.
* I left out 'ReusableWorkflowCallJob' since as far as I could tell, they did not have
  any naming capabilities

Closes: zizmorcore#795
@woodruffw
Copy link
Member

Thanks @andrewpollack! I'll give this a review later today.

@woodruffw woodruffw added the enhancement New feature or request label Jun 12, 2025
Copy link
Member

@woodruffw woodruffw left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @andrewpollack, this looks really great! Just some small feedback items.

Apart from that, this PR needs two things for merge-readiness:

  1. An update to audits.md with a new section documenting this audit; the other sections should be a good reference 🙂
  2. An update to release-notes.md under the "New Features" category, like with previous release notes for new audits

@woodruffw woodruffw self-requested a review June 12, 2025 15:39
@andrewpollack
Copy link
Contributor Author

Thank you for the review, this is great! I'll push updates later tonight

@andrewpollack
Copy link
Contributor Author

Added docs as part of 075cea0

andrewpollack and others added 2 commits June 12, 2025 16:40
@woodruffw
Copy link
Member

LGTM, thanks a ton @andrewpollack!

Signed-off-by: William Woodruff <william@yossarian.net>
@woodruffw woodruffw merged commit c6f0e29 into zizmorcore:main Jun 14, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

New audit: unnamed workflow/action definitions
2 participants
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载