You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Actionlint has an advantage over these tools though: It really understands advanced features like custom actions, reusable workflows etc. The tools I named are also hard to set up for private repositories, and actionlint is really easy to set up for private repositories.
The text was updated successfully, but these errors were encountered:
It would be nice to add an option to check for security best practices.
Best practices that could be supported:
GITHUB_TOKEN
permissionsSome other tools can already check for these things, like OSSF scorecard and StepSecurity SecureWorkflow.
Actionlint has an advantage over these tools though: It really understands advanced features like custom actions, reusable workflows etc. The tools I named are also hard to set up for private repositories, and actionlint is really easy to set up for private repositories.
The text was updated successfully, but these errors were encountered: