-
Notifications
You must be signed in to change notification settings - Fork 26
Open
Description
The accessibility-scanner workflow uses actions/github-script@v8 without pinning it to a specific commit SHA. This violates security best practices and causes the pipeline to fail when the Require actions to be pinned to a full-length commit SHA setting is enabled.
Steps to Reproduce
- Enable Require actions to be pinned to a full-length commit SHA in the repository settings.
- Run the
accessibility-scannerworkflow. - Observe the failure caused by the unpinned
actions/github-scriptaction.
Expected Behavior
The workflow should run successfully with all actions pinned to full-length commit SHAs.
Actual Behavior
The workflow fails because actions/github-script@v8 is not pinned to a commit SHA.
accessibility-scanner/action.yml
Line 137 in db51bb5
| uses: actions/github-script@v8 |
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Fields
Give feedbackNo fields configured for issues without a type.