-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Description
Security Alerts Requiring Manual Review
The following CodeQL alerts cannot be automatically fixed and require manual intervention:
Alert #50: actions/untrusted-checkout/high
- Severity: error
- File:
.github/workflows/automerge.yml:272 - Message: Potential execution of untrusted code on a privileged workflow (workflow_run)
Alert #47: actions/untrusted-checkout/high
- Severity: error
- File:
.github/workflows/automerge.yml:241 - Message: Potential execution of untrusted code on a privileged workflow (workflow_run)
Alert #8: actions/untrusted-checkout/high
- Severity: error
- File:
.github/workflows/automerge.yml:135 - Message: Potential execution of untrusted code on a privileged workflow (pull_request_target)
Potential execution of untrusted code on a privileged workflow (workflow_run)
Recommended Actions
- Review each alert in the Security tab
- Apply fixes following GitHub Security Lab recommendations
- Close alerts as fixed or false positive in dashboard
Auto-generated by security-autofix workflow
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels