insecure-tree report

Project: /home/runner/work/insecure_tree/insecure_tree
Source: pipdeptree
Scanned: 2026-05-17T02:16:15.793970+00:00
insecure-tree: 0.2.0   zizmor: 1.24.1

Summary

174
packages
170
with GitHub
163
scanned
137
with findings
2180
errors
909
warnings
2
pwn-request

pwn-request patterns

These workflows trigger on pull_request_target and call actions/checkout, which allows untrusted PR code to run with base-repo write permissions (pwn-request / GHSL-2021-041 class).

typer==0.25.1  — fastapi/typer
.github/workflows/latest-changes.yml → job latest-changes, step 2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
Workflow 'latest-changes.yml' triggers on pull_request_target and calls 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' in job 'latest-changes' (step 2). This combination lets untrusted PR code run with base-repo write permissions (pwn-request / GHSL-2021-041 class vulnerability).
annotated-doc==0.0.4  — fastapi/annotated-doc
.github/workflows/latest-changes.yml → job latest-changes, step 2
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
Workflow 'latest-changes.yml' triggers on pull_request_target and calls 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' in job 'latest-changes' (step 2). This combination lets untrusted PR code run with base-repo write permissions (pwn-request / GHSL-2021-041 class vulnerability).

Packages

Filter:
Package ↕ Repository ↕ Status ↕ Confidence ↕ Findings
aiohappyeyeballs==2.6.1 aio-libs/aiohappyeyeballs scanned high
21 errors 12 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:50
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:80
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:161
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:25
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:34
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:68
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:91
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:134
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:153
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:159
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:161
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:167
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/issue-manager.yml:18
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/issue-manager.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-manager.yml:21
unpinned action reference
View on GitHub
aiohttp==3.13.5 aio-libs/aiohttp scanned high
61 errors 1 warning 15 notes
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/auto-merge.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/auto-merge.yml:15
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/auto-merge.yml:11
spoofable bot actor check
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:61
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:130
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:186
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:296
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:377
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:422
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:514
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:587
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:663
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:215
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:215
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:325
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:325
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:131
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:135
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:142
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:187
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:192
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:202
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:221
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:264
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:278
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:297
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:302
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:312
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:328
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:356
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:363
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:378
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:383
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:395
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:405
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:423
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:428
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:440
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:464
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:484
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:488
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:515
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:519
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:528
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:539
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:588
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:593
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:610
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:621
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:629
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:634
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:664
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:671
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:680
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:694
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:697
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:707
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:77
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:135
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:142
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:202
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:312
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:383
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:707
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:28
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/label-remove.yml:20
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/labels.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/labels.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/stale.yml:13
unpinned action reference
View on GitHub
aiosignal==1.4.0 aio-libs/aiosignal scanned medium
15 errors 6 warnings 5 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:91
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:55
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:121
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:141
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:231
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:309
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:318
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:342
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:352
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:365
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:368
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:378
unpinned action reference
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:142
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:232
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:378
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:40
unpinned action reference
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/dependabot-auto-merge.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/dependabot-auto-merge.yml:15
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/dependabot-auto-merge.yml:11
spoofable bot actor check
View on GitHub
annotated-doc==0.0.4 fastapi/annotated-doc scanned high 1 pwn-request
6 errors 12 warnings 8 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/add-to-project.yml:11
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/add-to-project.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/detect-conflicts.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/issue-manager.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/labeler.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/latest-changes.yml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/latest-changes.yml:20
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/latest-changes.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:75
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/smokeshow.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/smokeshow.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-redistribute.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:13
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:47
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:64
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:104
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:25
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:99
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:141
overly broad permissions
View on GitHub
annotated-types==0.7.0 annotated-types/annotated-types scanned high
9 errors 7 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:51
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:71
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:13
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:47
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:63
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/ci.yml:91
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:81
unpinned action reference
View on GitHub
anyio==4.13.0 agronholm/anyio scanned high
39 errors 14 warnings 12 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:60
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/publish.yml:60
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-downstream.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-downstream.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-downstream.yml:66
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-downstream.yml:97
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-downstream.yml:125
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:32
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:56
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:89
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-downstream.yml:116
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test-downstream.yml:26
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test-downstream.yml:50
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test-downstream.yml:83
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test-downstream.yml:112
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test-downstream.yml:136
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:97
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:101
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:105
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:125
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-downstream.yml:129
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:99
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:149
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:9
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:36
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:59
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:138
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:161
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:101
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:133
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:149
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:151
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:167
unpinned action reference
View on GitHub
zizmor/unsound-condition: zizmor/unsound-condition
.github/workflows/test.yml:39
unsound conditional expression
View on GitHub
zizmor/unsound-condition: zizmor/unsound-condition
.github/workflows/test.yml:91
unsound conditional expression
View on GitHub
zizmor/unsound-condition: zizmor/unsound-condition
.github/workflows/test.yml:141
unsound conditional expression
View on GitHub
astroid==4.0.4 pylint-dev/astroid scanned high
35 errors 7 warnings 7 notes
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/backport.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:93
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:146
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:191
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:225
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:22
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:81
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:132
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:181
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:219
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:96
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:230
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:235
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:235
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:235
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql-analysis.yml:48
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:78
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:76
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-pylint.yml:7
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-pylint.yml:8
unpinned action reference
View on GitHub
attrs==26.1.0 python-attrs/attrs scanned high clean
bandit==1.9.4 PyCQA/bandit scanned high
14 errors 5 warnings 7 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-publish-image.yml:28
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/build-publish-image.yml:29
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/dependency-review.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/dependency-review.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/dependency-review.yml:14
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish-to-pypi.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:36
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish-to-test-pypi.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-test-pypi.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-test-pypi.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-test-pypi.yml:35
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pythonpackage.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pythonpackage.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pythonpackage.yml:60
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pythonpackage.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pythonpackage.yml:6
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pythonpackage.yml:25
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pythonpackage.yml:46
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:63
unpinned action reference
View on GitHub
black==26.3.1 psf/black scanned high
1 error 16 notes
zizmor/misfeature: zizmor/misfeature
.github/workflows/diff_shades.yml:48
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/diff_shades.yml:77
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/diff_shades.yml:132
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/diff_shades.yml:200
usage of GitHub Actions misfeatures
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/diff_shades_comment.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/diff_shades_comment.yml:37
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/docs.yml:38
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/fuzz.yml:41
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/lint.yml:35
usage of GitHub Actions misfeatures
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish_binaries.yml:67
code injection via template expansion
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/publish_binaries.yml:55
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/pypi_upload.yml:31
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/pypi_upload.yml:84
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/pypi_upload.yml:109
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release_tests.yml:45
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/test.yml:60
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/test.yml:120
usage of GitHub Actions misfeatures
View on GitHub
boolean.py==5.0 bastikr/boolean.py scanned medium
13 errors 12 warnings 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/pypi-release.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pypi-release.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pypi-release.yml:18
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pypi-release.yml:45
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pypi-release.yml:65
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/pypi-release.yml:80
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi-release.yml:80
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/pypi-release.yml:59
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-and-build.yml:35
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-and-build.yml:70
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-and-build.yml:83
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-and-build.yml:25
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-and-build.yml:30
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-and-build.yml:51
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-and-build.yml:78
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:83
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-and-build.yml:94
unpinned action reference
View on GitHub
CacheControl==0.14.4 psf/cachecontrol scanned high clean
cachetools==7.1.0 tkem/cachetools scanned high
1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
cattrs==26.1.0 python-attrs/cattrs scanned high clean
certifi==2026.4.22 certifi/python-certifi scanned high
4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/bump.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
cfgv==3.5.0 asottile/cfgv scanned medium
1 error 1 warning
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:11
unpinned action reference
View on GitHub
charset-normalizer==3.4.7 jawah/charset_normalizer scanned high
1 error 4 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/cd.yml:63
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/cd.yml:103
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/cd.yml:217
code injection via template expansion
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:203
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:47
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:54
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:57
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/scorecards.yml:69
action's hash pin has mismatched or missing version comment
View on GitHub
click==8.3.3 pallets/click scanned high clean
codespell==2.4.2 codespell-project/codespell scanned high
14 errors 1 note
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:15
unpinned action reference
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:55
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:91
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:98
unpinned action reference
View on GitHub
colorama==0.4.6 tartley/colorama scanned high
5 errors 4 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/lint_python.yml:7
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/lint_python.yml:4
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint_python.yml:7
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint_python.yml:8
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:41
unpinned action reference
View on GitHub
colorlog==6.10.1 borntyping/python-colorlog scanned medium
7 errors 6 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:44
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:68
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:4
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:27
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:80
unpinned action reference
View on GitHub
coverage==7.13.5 coveragepy/coveragepy scanned medium clean
crosshair-tool==0.0.104 pschanely/CrossHair scanned medium
17 errors 13 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/build_documentation.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_documentation.yml:15
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_documentation.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_documentation.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_documentation.yml:36
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/buildwheels.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/buildwheels.yml:54
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:50
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:65
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:81
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:86
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:39
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:19
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:42
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pyodide.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyodide.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyodide.yml:55
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test_hypothesis.yml:14
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test_hypothesis.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test_hypothesis.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test_hypothesis.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test_hypothesis.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test_hypothesis.yml:32
unpinned action reference
View on GitHub
cyclonedx-python-lib==11.7.0 CycloneDX/cyclonedx-python-lib scanned high
1 warning
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/release.yml:113
action's hash pin has mismatched or missing version comment
View on GitHub
deadcode==2.4.1 albertas/deadcode scanned high
2 errors 1 warning
zizmor/artipacked: zizmor/artipacked
.github/workflows/check-deadcode-on-python310.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check-deadcode-on-python310.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check-deadcode-on-python310.yml:23
unpinned action reference
View on GitHub
defusedxml==0.7.1 tiran/defusedxml scanned medium
11 errors 3 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:60
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:61
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pypi.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:98
unpinned action reference
View on GitHub
deptry==0.25.1 osprey-oss/deptry scanned high clean
dill==0.4.1 uqfoundation/dill no workflows high -
distlib==0.4.0 pypa/distlib scanned high
3 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/package-tests.yml:44
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/package-tests.yml:25
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/package-tests.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/package-tests.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/package-tests.yml:66
unpinned action reference
View on GitHub
distro==1.9.0 python-distro/distro scanned medium
10 errors 11 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:49
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:72
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:26
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:67
overly broad permissions
View on GitHub
zizmor/ref-confusion: zizmor/ref-confusion
.github/workflows/ci.yaml:63
git ref for action with ambiguous ref type
View on GitHub
zizmor/ref-confusion: zizmor/ref-confusion
.github/workflows/ci.yaml:74
git ref for action with ambiguous ref type
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:77
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:10
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/deploy.yml:27
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:18
unpinned action reference
View on GitHub
docstring_parser_fork==0.0.14 rr-/docstring_parser scanned high
13 errors 5 warnings 4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/apidocs.yml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/apidocs.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/apidocs.yml:10
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/apidocs.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/apidocs.yml:37
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:47
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:35
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:44
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:75
unpinned action reference
View on GitHub
execnet==2.1.2 pytest-dev/execnet scanned low
13 errors 5 warnings 4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:13
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:48
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:48
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:49
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:42
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:20
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:27
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:51
unpinned action reference
View on GitHub
filelock==3.29.0 tox-dev/py-filelock zizmor_failed high -
frozenlist==1.8.0 aio-libs/frozenlist scanned medium
35 errors 9 warnings 10 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:76
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:46
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:64
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:124
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:129
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:197
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:396
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:408
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:420
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:102
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:106
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:321
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:248
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:255
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:263
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:273
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:278
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:360
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:384
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:404
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:493
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:501
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:512
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:526
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:529
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:539
unpinned action reference
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:131
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:422
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:539
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:46
unpinned action reference
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/dependabot-auto-merge.yml:4
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/dependabot-auto-merge.yml:18
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/dependabot-auto-merge.yml:14
spoofable bot actor check
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-cibuildwheel.yml:88
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:117
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/reusable-linters.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:70
unpinned action reference
View on GitHub
gha-update==0.2.0 davidism/gha-update scanned high
2 errors 7 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yaml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yaml:7
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yaml:9
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:6
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:32
code injection via template expansion
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/publish.yaml:45
action has a known vulnerability
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/publish.yaml:10
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:23
overly broad permissions
View on GitHub
ghp-import==2.1.0 c-w/ghp-import scanned medium
6 errors 7 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/cd.yaml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/cd.yaml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/cd.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/cd.yaml:9
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/cd.yaml:22
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cd.yaml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cd.yaml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cd.yaml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cd.yaml:28
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:16
unpinned action reference
View on GitHub
git2md==1.1.7 xpos587/git2md scanned medium
13 errors 9 warnings 4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yaml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yaml:72
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yaml:122
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yaml:147
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yaml:15
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yaml:42
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yaml:68
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yaml:140
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yaml:27
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yaml:59
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yaml:81
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yaml:138
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yaml:138
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:75
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:113
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:123
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:147
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yaml:155
unpinned action reference
View on GitHub
zizmor/unpinned-images: zizmor/unpinned-images
.github/workflows/release.yaml:145
unpinned image references
View on GitHub
griffe==2.0.2 mkdocstrings/griffe scanned high
16 errors 7 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:53
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:125
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:29
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:95
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:132
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:138
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:150
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:26
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:26
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sponsors.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:19
unpinned action reference
View on GitHub
griffecli==2.0.2 - no repo - -
griffelib==2.0.2 - no repo - -
grimp==3.14 python-grimp/grimp scanned medium
35 errors 12 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:47
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:66
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:35
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:63
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:80
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:73
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:106
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:139
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:164
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:91
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:118
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:139
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:140
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:156
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:164
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:166
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:171
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:182
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:184
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:47
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:84
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:118
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:150
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
h11==0.16.0 python-hyper/h11 scanned medium
3 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:41
unpinned action reference
View on GitHub
h2==4.3.0 python-hyper/h2 scanned high
3 errors 1 warning 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:41
unpinned action reference
View on GitHub
hpack==4.1.0 python-hyper/hpack scanned high
3 errors 1 warning 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:36
unpinned action reference
View on GitHub
httpcore==1.0.9 encode/httpcore scanned high
4 errors 4 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:18
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-suite.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-suite.yml:11
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-suite.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-suite.yml:21
unpinned action reference
View on GitHub
httpx==0.28.1 encode/httpx scanned high
4 errors 4 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:18
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-suite.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-suite.yml:11
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-suite.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test-suite.yml:21
unpinned action reference
View on GitHub
hyperframe==6.1.0 python-hyper/hyperframe scanned high
3 errors 1 warning 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:38
unpinned action reference
View on GitHub
hypothesis==6.152.4 HypothesisWorks/hypothesis scanned high
20 errors 19 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/fuzz.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/fuzz.yml:19
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:87
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:110
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:179
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:229
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:261
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:316
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:22
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:62
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:139
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:197
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:249
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:296
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:306
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:110
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:179
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:229
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:261
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:302
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:316
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/update-deps.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/update-deps.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/update-deps.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/update-deps.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/update-deps.yml:21
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/website.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:43
unpinned action reference
View on GitHub
identify==2.6.19 pre-commit/identify scanned medium
1 error 1 warning
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:11
unpinned action reference
View on GitHub
idna==3.13 kjd/idna scanned high
2 errors 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:79
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:90
code injection via template expansion
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-package.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-package.yml:48
credential persistence through GitHub Actions artifacts
View on GitHub
import-linter==2.11 seddonym/import-linter scanned medium
15 errors 10 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:66
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:85
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:30
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:56
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:80
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:85
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:91
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:25
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:25
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:20
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
importlib_metadata==9.0.0 python/importlib_metadata scanned high
7 errors 3 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:84
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:122
unpinned action reference
View on GitHub
importlib_resources==7.1.0 python/importlib_resources scanned high
7 errors 3 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:84
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:122
unpinned action reference
View on GitHub
iniconfig==2.3.0 pytest-dev/iniconfig scanned high
11 errors 5 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:42
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:28
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test.yml:68
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:83
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:117
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:136
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:142
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/test.yml:93
action functionality is already included by the runner
View on GitHub
insecure_tree==0.3.0 matthewdeanmartin/insecure_tree scanned high clean
interrogate==1.7.0 econchick/interrogate scanned high
32 errors 24 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:39
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:114
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:127
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:146
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:4
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:20
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:31
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:73
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:109
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:120
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:142
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:157
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:67
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:103
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:114
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:118
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:146
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:147
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:171
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pypi.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pypi.yml:16
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pypi.yml:66
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sanity.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sanity.yml:47
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sanity.yml:62
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/sanity.yml:6
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/sanity.yml:19
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/sanity.yml:43
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/sanity.yml:58
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sanity.yml:63
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/windows.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/windows.yml:13
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/windows.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/windows.yml:21
unpinned action reference
View on GitHub
isort==8.0.1 PyCQA/isort scanned high
25 errors 4 warnings 6 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/continuous-integration.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/continuous-integration.yml:56
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/continuous-integration.yml:75
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/continuous-integration.yml:100
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/continuous-integration.yml:38
unpinned action reference
View on GitHub
zizmor/unsound-condition: zizmor/unsound-condition
.github/workflows/continuous-integration.yml:91
unsound conditional expression
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/labeler.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/labeler.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/labeler.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/labeler.yml:17
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release-drafter.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-drafter.yml:14
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:79
unpinned action reference
View on GitHub
jiggle_version==2.1.1 - no repo - -
Jinja2==3.1.6 pallets/jinja scanned high
2 errors 10 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yaml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yaml:7
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yaml:9
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:6
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:32
code injection via template expansion
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/publish.yaml:45
action has a known vulnerability
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/publish.yaml:10
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:9
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:33
overly broad permissions
View on GitHub
jiter==0.14.0 pydantic/jiter scanned low
2 notes
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/ci.yml:676
prefer trusted publishing for authentication
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci.yml:729
action functionality is already included by the runner
View on GitHub
joblib==1.5.3 joblib/joblib scanned high
17 errors 2 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/codespell.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:25
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-pypi.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-pypi.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:117
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish-to-pypi.yml:122
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:125
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:147
unpinned action reference
View on GitHub
librt==0.9.0 mypyc/librt scanned high
9 errors 6 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/buildwheels.yml:88
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/buildwheels.yml:119
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:15
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:76
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/buildwheels.yml:115
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:96
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:101
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:109
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:119
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:130
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:143
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/buildwheels.yml:151
unpinned action reference
View on GitHub
license-expression==30.4.4 aboutcode-org/license-expression scanned medium
1 note
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/pypi-release.yml:69
action functionality is already included by the runner
View on GitHub
linkcheckmd==1.4.0 scivision/linkchecker-markdown scanned medium
4 errors 3 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:11
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:23
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codespell.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:23
unpinned action reference
View on GitHub
llvm-diagnostics==3.0.1 tomtom-international/llvm-diagnostics scanned medium
11 errors 12 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/build_and_test.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build_and_test.yml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build_and_test.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build_and_test.yml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_and_test.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_and_test.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_and_test.yml:32
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_and_test.yml:53
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build_and_test.yml:74
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_and_test.yml:81
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/quality_checks.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/quality_checks.yml:13
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:12
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:34
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:19
unpinned action reference
View on GitHub
loguru==0.7.3 Delgan/loguru scanned high
19 errors 7 warnings 6 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql-analysis.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:31
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/docs.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:13
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/lint.yml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/lint.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint.yml:13
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/packaging.yml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/packaging.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/packaging.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/packaging.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/packaging.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/packaging.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/packaging.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/packaging.yml:44
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:50
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:75
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:10
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:71
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:80
unpinned action reference
View on GitHub
lsprotocol==2025.0.0 microsoft/lsprotocol scanned high
59 errors 33 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql-analysis.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/dep-bot-auto-merge.yml:15
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/dep-bot-auto-merge.yml:11
spoofable bot actor check
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-labels.yml:16
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:49
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:102
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:122
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:146
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:177
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pr-check.yml:213
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:7
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:45
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:92
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:118
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:138
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:169
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-check.yml:209
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:103
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:123
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:147
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:155
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:178
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:181
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:186
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:214
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:217
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-check.yml:232
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pr-labels.yml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pr-labels.yml:17
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:54
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:107
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:131
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:162
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/push-check.yml:194
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:50
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:97
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:123
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:154
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push-check.yml:190
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:108
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:132
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:135
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:140
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:163
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:166
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:171
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:195
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:198
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push-check.yml:213
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/push-check.yml:25
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/push-check.yml:63
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/push-check.yml:79
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/updater.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/updater.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/updater.yml:19
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/version-check.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/version-check.yml:7
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/version-check.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/version-check.yml:15
unpinned action reference
View on GitHub
maison==2.0.2 dbatten/maison github_api_failed high -
Markdown==3.10.2 Python-Markdown/markdown scanned high
25 errors 23 warnings 3 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/changelog-enforcer.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-enforcer.yml:15
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/changelog-validator.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/changelog-validator.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/changelog-validator.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/changelog-validator.yml:10
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/changelog-validator.yml:25
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-validator.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-validator.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-validator.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-validator.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog-validator.yml:43
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:59
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:10
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:52
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/deploy.yml:26
prefer trusted publishing for authentication
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:32
code injection via template expansion
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/deploy.yml:26
action has a known vulnerability
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:66
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/deploy.yml:42
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/manual_deploy.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/manual_deploy.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/manual_deploy.yml:14
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/manual_deploy.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/manual_deploy.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/manual_deploy.yml:29
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tox.yml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tox.yml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:66
overly broad permissions
View on GitHub
zizmor/ref-confusion: zizmor/ref-confusion
.github/workflows/tox.yml:59
git ref for action with ambiguous ref type
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:80
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/version_check.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/version_check.yml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/version_check.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/version_check.yml:17
unpinned action reference
View on GitHub
markdown-it-py==4.0.0 executablebooks/markdown-it-py scanned high
22 errors 16 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/benchmark.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/benchmark.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/benchmark.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/benchmark.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/benchmark.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/benchmark.yml:40
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/copilot-setup-steps.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/copilot-setup-steps.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/copilot-setup-steps.yml:24
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/fuzz.yml:16
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/fuzz.yml:32
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:71
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:91
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:4
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:17
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:29
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:64
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:87
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:113
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:136
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:73
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:91
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:94
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:121
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:123
unpinned action reference
View on GitHub
MarkupSafe==3.0.3 pallets/markupsafe scanned high
6 errors 12 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yaml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yaml:7
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yaml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yaml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yaml:38
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:81
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:81
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:89
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/publish.yaml:89
code injection via template expansion
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/publish.yaml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/publish.yaml:47
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:42
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:9
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:39
overly broad permissions
View on GitHub
mccabe==0.7.0 pycqa/mccabe no workflows medium -
mdformat==1.0.0 hukkin/mdformat scanned high
10 errors 11 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:41
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:71
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:74
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:99
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:32
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:63
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:85
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:93
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/tests.yaml:112
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:100
unpinned action reference
View on GitHub
mdurl==0.1.2 executablebooks/mdurl scanned high
7 errors 8 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:76
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:31
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:62
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:70
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/tests.yaml:89
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:77
unpinned action reference
View on GitHub
mergedeep==1.3.4 clarketm/mergedeep no workflows medium -
metametameta==0.1.11 matthewdeanmartin/metametameta scanned low clean
mkdocs==1.6.1 mkdocs/mkdocs scanned high
16 errors 13 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/autofix.yml:9
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/autofix.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:9
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:23
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:58
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:89
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:55
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:86
overly broad permissions
View on GitHub
zizmor/ref-confusion: zizmor/ref-confusion
.github/workflows/ci.yml:48
git ref for action with ambiguous ref type
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:67
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:91
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy-release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:22
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/docs.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:14
unpinned action reference
View on GitHub
mkdocs-autorefs==1.4.4 mkdocstrings/autorefs scanned high
13 errors 6 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:53
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:122
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:29
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:92
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:65
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:86
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:123
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:135
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:147
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:26
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:26
action functionality is already included by the runner
View on GitHub
mkdocs-get-deps==0.2.2 mkdocs/get-deps scanned high
10 errors 8 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/autofix.yml:9
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/autofix.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:10
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/autofix.yml:29
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:52
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:58
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy-release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy-release.yml:22
unpinned action reference
View on GitHub
mkdocstrings==1.0.4 mkdocstrings/mkdocstrings scanned high
15 errors 7 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:54
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:123
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:30
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:93
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:130
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:136
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:148
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:26
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:26
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sponsors.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:19
unpinned action reference
View on GitHub
mkdocstrings-python==2.0.3 mkdocstrings/python scanned high
15 errors 7 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:50
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:119
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:29
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:89
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:83
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:132
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:144
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:26
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:26
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sponsors.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sponsors.yml:19
unpinned action reference
View on GitHub
msgpack==1.1.2 msgpack/msgpack-python scanned high
6 warnings 4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yaml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/docs.yaml:6
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/lint.yaml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/lint.yaml:6
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:9
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wheel.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/wheel.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/wheel.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/wheel.yml:68
overly broad permissions
View on GitHub
multidict==6.7.1 aio-libs/multidict scanned medium
43 errors 10 warnings 11 notes
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/auto-merge.yml:4
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/auto-merge.yml:18
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/auto-merge.yml:14
spoofable bot actor check
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:67
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:400
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:37
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:55
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:107
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:110
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:164
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:393
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:425
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:476
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:488
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:85
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:89
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:355
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:94
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:222
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:230
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:237
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:273
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:299
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:366
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:390
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:401
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:404
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:410
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:416
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:438
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:442
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:449
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:467
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:547
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:555
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:566
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:583
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:586
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:596
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:273
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci-cd.yml:404
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:112
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:490
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:596
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:45
unpinned action reference
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-cibuildwheel.yml:88
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:117
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/reusable-linters.yml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:60
unpinned action reference
View on GitHub
mypy==1.20.2 python/mypy scanned high
19 errors
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_wheels.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build_wheels.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer.yml:86
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer.yml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer_comment.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/mypy_primer_comment.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sync_typeshed.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sync_typeshed.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:163
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:201
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:256
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:276
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test_stubgenc.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test_stubgenc.yml:36
unpinned action reference
View on GitHub
mypy_extensions==1.1.0 python/mypy_extensions scanned high
4 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:25
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:58
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:60
unpinned action reference
View on GitHub
nltk==3.9.4 nltk/nltk scanned high
21 errors 11 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/cffconvert.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cffconvert.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cffconvert.yml:21
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:25
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:82
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yml:129
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yml:140
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yml:151
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:82
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:85
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:115
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:132
unpinned action reference
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/labeler.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/labeler.yml:12
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:35
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:49
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:49
action functionality is already included by the runner
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/retest-pr.yml:55
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/retest-pr.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/retest-pr.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/retest-pr.yml:48
unpinned action reference
View on GitHub
nodeenv==1.10.0 ekalinin/nodeenv scanned medium
12 errors 10 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:52
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:67
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:79
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:43
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:40
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:62
unpinned action reference
View on GitHub
openai==2.33.0 openai/openai-python scanned high
1 error 12 warnings 7 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:47
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:86
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:107
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:18
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:80
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:100
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/create-releases.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/create-releases.yml:10
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/detect-breaking-changes.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/detect-breaking-changes.yml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/detect-breaking-changes.yml:63
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/detect-breaking-changes.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/detect-breaking-changes.yml:9
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/detect-breaking-changes.yml:40
overly broad permissions
View on GitHub
zizmor/impostor-commit: zizmor/impostor-commit
.github/workflows/detect-breaking-changes.yml:69
commit with no history in referenced repository
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/detect-breaking-changes.yml:69
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish-pypi.yml:14
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-pypi.yml:8
overly broad permissions
View on GitHub
packageurl-python==0.17.6 package-url/packageurl-python scanned medium
2 warnings
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:38
overly broad permissions
View on GitHub
packaging==26.2 pypa/packaging scanned high
5 warnings
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:46
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:58
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/codeql.yml:61
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/publish.yml:69
action's hash pin has mismatched or missing version comment
View on GitHub
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/publish.yml:92
action's hash pin has mismatched or missing version comment
View on GitHub
pathspec==1.1.1 cpburnz/python-pathspec scanned high
4 warnings 4 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-pypi.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-pypi.yaml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-testpypi.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish-to-testpypi.yaml:8
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-all.yaml:66
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-all.yaml:100
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-quick.yaml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-quick.yaml:64
credential persistence through GitHub Actions artifacts
View on GitHub
pip==26.1 pypa/pip scanned high
1 warning
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/release.yml:18
action's hash pin has mismatched or missing version comment
View on GitHub
pip-api==0.0.34 di/pip-api scanned medium
17 errors 9 warnings 5 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pip-feed.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pip-feed.yml:11
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:44
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/release.yml:44
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:69
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:18
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:32
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:62
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:80
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:103
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:123
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test.yml:101
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:110
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:115
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:131
unpinned action reference
View on GitHub
pip_audit==2.10.0 pypa/pip-audit scanned high clean
pip-requirements-parser==32.0.1 nexB/pip-requirements-parser zizmor_failed medium -
pipdeptree==2.35.2 tox-dev/pipdeptree scanned high clean
platformdirs==4.9.6 tox-dev/platformdirs scanned high clean
pluggy==1.6.0 pytest-dev/pluggy scanned low clean
pre_commit==4.6.0 pre-commit/pre-commit scanned medium
8 errors 8 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/languages.yaml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/languages.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/languages.yaml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/languages.yaml:30
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/languages.yaml:77
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/languages.yaml:68
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:19
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:20
unpinned action reference
View on GitHub
prompt_toolkit==3.0.52 prompt-toolkit/python-prompt-toolkit scanned high
3 errors 1 warning 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yaml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yaml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yaml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yaml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yaml:46
unpinned action reference
View on GitHub
propcache==0.4.1 aio-libs/propcache scanned medium
45 errors 10 warnings 12 notes
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/auto-merge.yml:4
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/auto-merge.yml:18
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/auto-merge.yml:14
spoofable bot actor check
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:76
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:231
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:393
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:46
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:64
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:126
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:131
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:188
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:384
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:476
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:488
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:500
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:104
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:108
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:306
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:468
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:113
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:232
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:234
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:241
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:248
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:258
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:263
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:344
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:372
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:394
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:396
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:403
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:411
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:420
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:425
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:470
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:484
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:556
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:564
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:575
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:589
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:592
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:602
unpinned action reference
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:133
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:502
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:602
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:45
unpinned action reference
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-build-wheel.yml:76
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-build-wheel.yml:82
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-build-wheel.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-build-wheel.yml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-build-wheel.yml:86
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-build-wheel.yml:94
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/reusable-linters.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:70
unpinned action reference
View on GitHub
py==1.11.0 pytest-dev/py scanned low
5 errors 5 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:50
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:6
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:41
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/main.yml:63
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:63
unpinned action reference
View on GitHub
py-serializable==2.1.0 madpah/serializable scanned high
22 errors 7 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/python.yml:51
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python.yml:75
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python.yml:109
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python.yml:164
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:86
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:114
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:166
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:171
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:177
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python.yml:194
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:69
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:103
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:142
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:105
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:117
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:132
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:142
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:149
unpinned action reference
View on GitHub
pyclean==3.6.0 bittner/pyclean scanned high
6 errors 3 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:20
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:33
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:17
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:21
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:20
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:41
unpinned action reference
View on GitHub
pydantic==2.13.3 pydantic/pydantic scanned high clean
pydantic_core==2.46.3 pydantic/pydantic-core scanned low
98 errors 36 warnings 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:84
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:124
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:153
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:196
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:222
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:227
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:264
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:299
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:318
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:390
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:490
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:541
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:574
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:615
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:670
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:699
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:60
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:114
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:148
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:184
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:217
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:260
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:294
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:315
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:366
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:386
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:404
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:518
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:569
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:600
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:652
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:130
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:133
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:153
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:156
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:166
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:171
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:196
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:199
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:204
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:207
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:222
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:227
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:232
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:235
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:238
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:264
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:267
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:272
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:275
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:280
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:299
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:302
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:305
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:307
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:318
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:321
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:329
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:331
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:340
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:348
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:360
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:381
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:390
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:391
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:394
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:399
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:490
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:493
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:501
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:513
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:541
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:544
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:550
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:564
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:574
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:577
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:615
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:618
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:624
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:670
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:673
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:676
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:699
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:701
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:707
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:719
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:725
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:24
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:28
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:90
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:95
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:130
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:133
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:156
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:171
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:199
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:207
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:235
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:238
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:272
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:275
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:280
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:305
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:329
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:340
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:348
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:544
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:673
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:701
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci.yml:725
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codspeed.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/codspeed.yml:17
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/codspeed.yml:60
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:63
unpinned action reference
View on GitHub
pydantic-settings==2.14.0 pydantic/pydantic-settings scanned high clean
pydoclint==0.8.3 jsh9/pydoclint scanned high
7 errors 6 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-package.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-package.yml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/python-package.yml:4
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/python-package.yml:11
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/python-package.yml:31
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:38
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-publish.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/python-publish.yml:32
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-publish.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-publish.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-publish.yml:32
unpinned action reference
View on GitHub
pydoctest==0.2.1 jepperaskdk/pydoctest scanned medium
5 errors 4 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-package.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/python-package.yml:14
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-package.yml:45
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/python-publish.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/python-publish.yml:11
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/python-publish.yml:31
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-publish.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/python-publish.yml:18
unpinned action reference
View on GitHub
pyenchant==3.3.0 pyenchant/pyenchant scanned high
12 errors 8 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/linters.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/linters.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/linters.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/linters.yml:16
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:50
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:22
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/website.yml:14
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/website.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/website.yml:31
unpinned action reference
View on GitHub
pygls==2.1.1 openlawlibrary/pygls scanned low
14 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:91
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:108
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:28
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:50
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:86
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:103
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/json-extension.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/json-extension.yml:13
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:8
overly broad permissions
View on GitHub
Pygments==2.20.0 pygments/pygments scanned high
12 errors 5 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yaml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yaml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yaml:59
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yaml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yaml:80
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/build.yaml:32
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yaml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yaml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yaml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yaml:36
unpinned action reference
View on GitHub
pylint==4.0.5 pylint-dev/pylint scanned high
82 errors 17 notes
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/backport.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/changelog.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/changelog.yml:65
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/changelog.yml:44
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/checks.yaml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/checks.yaml:93
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/checks.yaml:129
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/checks.yaml:144
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/checks.yaml:98
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql-analysis.yml:50
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql-analysis.yml:80
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer-test.yaml:37
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer-test.yaml:80
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer-test.yaml:84
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer_comment.yaml:34
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/primer_comment.yaml:9
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/primer_comment.yaml:98
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_comment.yaml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_comment.yaml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_comment.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_comment.yaml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_comment.yaml:104
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer_run_main.yaml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:85
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:105
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_main.yaml:126
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer_run_pr.yaml:45
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/primer_run_pr.yaml:184
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:154
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:167
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:200
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:208
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer_run_pr.yaml:222
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/stale.yml:16
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:124
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:165
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:206
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/tests.yaml:72
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/tests.yaml:96
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/tests.yaml:212
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/tests.yaml:227
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:134
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:142
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:148
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:134
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:184
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:79
unpinned action reference
View on GitHub
pymdown-extensions==10.21.2 facelessuser/pymdown-extensions scanned high
19 errors 11 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:44
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:102
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:66
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:90
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:102
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:104
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:108
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/build.yml:108
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:43
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:41
unpinned action reference
View on GitHub
pyparsing==3.3.2 pyparsing/pyparsing scanned high
5 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:35
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:38
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/cifuzz.yml:4
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cifuzz.yml:9
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cifuzz.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cifuzz.yml:22
unpinned action reference
View on GitHub
pyphen==0.17.2 Kozea/Pyphen scanned high
2 errors 3 warnings
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/doconfly.yml:10
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:5
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:19
unpinned action reference
View on GitHub
pyproject-api==1.10.0 tox-dev/pyproject-api scanned high clean
pytest==9.0.3 pytest-dev/pytest scanned high
1 warning
zizmor/ref-version-mismatch: zizmor/ref-version-mismatch
.github/workflows/stale.yml:13
action's hash pin has mismatched or missing version comment
View on GitHub
pytest-cov==7.1.0 pytest-dev/pytest-cov scanned medium
6 errors 5 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:226
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:4
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:45
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:246
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:226
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:229
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:256
unpinned action reference
View on GitHub
pytest-mock==3.15.1 pytest-dev/pytest-mock scanned high
15 errors 2 warnings 5 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:57
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:57
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:58
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:72
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/deploy.yml:72
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:55
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:31
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:64
unpinned action reference
View on GitHub
pytest-randomly==4.1.0 pytest-dev/pytest-randomly scanned high
15 errors 3 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:58
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:103
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:53
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:60
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:65
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:103
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:105
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:110
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/main.yml:38
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/main.yml:65
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/main.yml:105
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
pytest-sugar==1.1.1 Teemu/pytest-sugar scanned medium
4 errors 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-and-test.yaml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-and-test.yaml:58
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-test.yaml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-test.yaml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-test.yaml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-test.yaml:61
unpinned action reference
View on GitHub
pytest-timeout==2.4.0 pytest-dev/pytest-timeout scanned medium
2 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:5
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:29
unpinned action reference
View on GitHub
pytest-xdist==3.8.0 pytest-dev/pytest-xdist scanned high
14 errors 5 warnings 5 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:13
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:50
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:50
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/deploy.yml:51
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:54
unpinned action reference
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/deploy.yml:54
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:72
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:20
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:27
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:84
unpinned action reference
View on GitHub
python-dateutil==2.9.0.post0 dateutil/dateutil scanned high
12 errors 12 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:25
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:22
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:27
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/validate.yml:63
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/validate.yml:111
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/validate.yml:128
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/validate.yml:142
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/validate.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/validate.yml:15
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/validate.yml:102
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/validate.yml:125
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/validate.yml:139
overly broad permissions
View on GitHub
zizmor/ref-confusion: zizmor/ref-confusion
.github/workflows/validate.yml:93
git ref for action with ambiguous ref type
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:67
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:115
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:131
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:142
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/validate.yml:144
unpinned action reference
View on GitHub
zizmor/unpinned-images: zizmor/unpinned-images
.github/workflows/validate.yml:58
unpinned image references
View on GitHub
python-discovery==1.2.2 tox-dev/python-discovery scanned high clean
python-dotenv==1.2.2 theskumar/python-dotenv scanned high
6 errors 1 warning 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:44
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:34
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:14
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:37
unpinned action reference
View on GitHub
pytokens==0.4.1 tusharsadhwani/pytokens scanned high
13 errors 2 warnings 4 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/primer.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/primer.yml:42
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tox.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:25
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wheels.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wheels.yml:62
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wheels.yml:78
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wheels.yml:102
unpinned action reference
View on GitHub
PyYAML==6.0.3 yaml/pyyaml scanned high
27 errors 24 warnings 5 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:81
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:116
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:141
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:285
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:305
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:493
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:39
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:76
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:95
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:136
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:188
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:264
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:300
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:379
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:449
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:488
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:576
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:646
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:657
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:240
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:244
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:426
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:474
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:474
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yaml:623
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:81
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:113
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:117
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:141
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:199
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:205
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:212
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:257
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:280
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:286
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:305
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:392
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:398
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:405
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:442
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:461
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:493
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:592
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:598
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:605
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:639
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:651
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:668
unpinned action reference
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci.yaml:464
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci.yaml:601
obfuscated usage of GitHub Actions features
View on GitHub
pyyaml_env_tag==1.1 waylan/pyyaml-env-tag scanned high
10 errors 7 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:53
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:50
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:54
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:52
unpinned action reference
View on GitHub
refurb==2.3.1 dosisod/refurb scanned high
4 errors 4 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:25
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:32
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:14
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/deploy.yml:10
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/deploy.yml:24
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:14
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:16
unpinned action reference
View on GitHub
regex==2026.4.4 mrabarnett/mrab-regex scanned high
20 errors 11 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:84
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:133
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:162
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:17
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:39
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:67
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:115
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:148
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:182
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/main.yml:195
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:85
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:133
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:134
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:139
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:142
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:162
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:163
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:168
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:173
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:176
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:188
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:195
unpinned action reference
View on GitHub
requests==2.33.1 psf/requests scanned high clean
requirements-parser==0.13.0 madpah/requirements-parser scanned high
16 errors 8 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:63
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:79
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/deploy.yml:94
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/poetry.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/poetry.yml:67
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/poetry.yml:106
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/poetry.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/poetry.yml:26
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/poetry.yml:50
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/poetry.yml:86
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:69
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:108
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:113
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:121
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/poetry.yml:141
unpinned action reference
View on GitHub
rich==15.0.0 Textualize/rich scanned high
12 errors 8 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:63
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codespell.yml:7
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/codespell.yml:4
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codespell.yml:7
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/newissue.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/newissue.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/newissue.yml:22
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pythonpackage.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pythonpackage.yml:6
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pythonpackage.yml:47
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/readmechanged.yml:14
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/readmechanged.yml:11
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/readmechanged.yml:14
unpinned action reference
View on GitHub
rich-argparse==1.8.0 hamdanal/rich-argparse scanned high
5 errors 2 warnings 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-tests.yml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/nightly-tests.yml:22
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-tests.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-tests.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-tests.yml:33
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:19
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:33
unpinned action reference
View on GitHub
ruff==0.15.12 astral-sh/ruff scanned high
2 errors 10 warnings 3 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:18
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:106
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:181
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:234
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:330
code injection via template expansion
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:120
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:130
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:144
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:251
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:266
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:336
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:345
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:354
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:363
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:372
secrets unconditionally inherited by called workflow
View on GitHub
ruyaml==0.91.0 pycontribs/ruyaml scanned high
11 errors 8 warnings 2 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ack.yml:8
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/ack.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ack.yml:9
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/push.yml:11
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/push.yml:12
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:8
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:39
prefer trusted publishing for authentication
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:46
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:46
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tox.yml:35
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:6
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tox.yml:72
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tox.yml:68
unpinned action reference
View on GitHub
semantic-version==2.10.0 rbarrois/python-semanticversion scanned medium
4 errors 4 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:25
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:36
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:39
unpinned action reference
View on GitHub
setuptools==82.0.1 pypa/setuptools scanned high
24 errors 9 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-sage.yml:60
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-sage.yml:74
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-sage.yml:74
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-sage.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-sage.yml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-sage.yml:83
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:72
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:155
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:196
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:249
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:289
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:317
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/main.yml:114
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:82
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:100
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:136
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:155
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:159
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:181
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:196
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:198
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:234
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:250
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:255
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:261
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:289
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:295
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:317
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:319
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/main.yml:100
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pyright.yml:52
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pyright.yml:40
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyright.yml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyright.yml:54
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyright.yml:73
unpinned action reference
View on GitHub
shellingham==1.5.4 sarugaku/shellingham scanned medium
8 errors 6 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:20
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:29
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:32
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:13
overly broad permissions
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/publish.yml:50
action has a known vulnerability
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:50
unpinned action reference
View on GitHub
six==1.17.0 benjaminp/six scanned medium
5 errors 4 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:67
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:67
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-images: zizmor/unpinned-images
.github/workflows/ci.yml:63
unpinned image references
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:10
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/publish.yml:39
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:15
unpinned action reference
View on GitHub
sniffio==1.3.1 python-trio/sniffio scanned high
7 errors 5 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:71
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:6
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:31
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:62
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:90
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:99
unpinned action reference
View on GitHub
sortedcontainers==2.4.0 quantopian/zipline scanned low
5 errors 4 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:55
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/windows_ci.yml:25
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/windows_ci.yml:16
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/windows_ci.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/windows_ci.yml:48
unpinned action reference
View on GitHub
stevedore==5.7.0 - no repo - -
tabulate==0.10.0 astanin/python-tabulate scanned high
5 errors 2 warnings 2 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/lint.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/lint.yml:8
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/lint.yml:17
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tabulate.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tabulate.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tabulate.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tabulate.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tabulate.yml:31
unpinned action reference
View on GitHub
termcolor==3.3.0 termcolor/termcolor scanned high clean
textstat==0.7.13 textstat/textstat scanned medium
2 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:13
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:24
unpinned action reference
View on GitHub
toml==0.10.2 uiri/toml scanned medium
2 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yaml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yaml:12
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yaml:21
unpinned action reference
View on GitHub
tomli==2.4.1 hukkin/tomli scanned high
15 errors 8 warnings 6 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:47
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:65
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:92
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:19
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:38
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:62
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:84
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:115
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:134
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:145
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/tests.yaml:165
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:65
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:94
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:104
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:109
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:151
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:156
unpinned action reference
View on GitHub
tomli_w==1.2.0 hukkin/tomli-w scanned high
7 errors 8 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yaml:75
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:31
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:61
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yaml:69
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/tests.yaml:88
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:43
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:75
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yaml:76
unpinned action reference
View on GitHub
tomlkit==0.14.0 sdispater/tomlkit zizmor_failed high -
totalhelp==0.1.1 matthewdeanmartin/totalhelp scanned high clean
tox==4.53.1 tox-dev/tox scanned high clean
tox-uv==1.35.1 tox-dev/tox-uv scanned high clean
tox-uv-bare==1.35.1 tox-dev/tox-uv scanned high clean
tqdm==4.67.3 tqdm/tqdm scanned high
29 errors 9 warnings 14 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:18
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/check.yml:68
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:26
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/check.yml:63
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/check.yml:81
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/comment-bot.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/comment-bot.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/comment-bot.yml:15
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/post-release.yml:10
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/post-release.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/post-release.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/post-release.yml:7
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/post-release.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/post-release.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/post-release.yml:18
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/post-release.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/post-release.yml:43
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:11
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:53
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:116
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unsound-contains: zizmor/unsound-contains
.github/workflows/test.yml:8
unsound contains condition
View on GitHub
zizmor/unsound-contains: zizmor/unsound-contains
.github/workflows/test.yml:39
unsound contains condition
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:7
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:38
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:89
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test.yml:151
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/test.yml:151
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:11
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:53
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:55
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:116
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:154
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:157
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:164
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:172
unpinned action reference
View on GitHub
troml-dev-status==0.6.1 matthewdeanmartin/troml_dev_status scanned high clean
typer==0.25.1 fastapi/typer scanned high 1 pwn-request
8 errors 16 warnings 13 notes
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/add-to-project.yml:11
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/add-to-project.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-docs.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-docs.yml:49
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-docs.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-docs.yml:39
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-docs.yml:76
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/conflict.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/deploy-docs.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/deploy-docs.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/deploy-docs.yml:29
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/issue-manager.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/labeler.yml:2
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/latest-changes.yml:27
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/latest-changes.yml:20
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/latest-changes.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:14
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:77
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/smokeshow.yml:21
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/smokeshow.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-cpython-nightly.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-cpython-nightly.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-cpython-nightly.yml:12
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test-redistribute.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:13
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test-redistribute.yml:50
overly broad permissions
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:49
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:85
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:19
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:77
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:116
overly broad permissions
View on GitHub
typeshed_client==2.11.0 JelleZijlstra/typeshed_client scanned medium
13 errors 10 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/publish.yml:13
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/publish.yml:9
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/publish.yml:34
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:13
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:34
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/sync-typeshed.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sync-typeshed.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sync-typeshed.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/sync-typeshed.yml:63
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:15
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/test.yml:44
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:8
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:26
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/test.yml:40
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:15
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/test.yml:46
unpinned action reference
View on GitHub
typing_extensions==4.15.0 python/typing_extensions scanned high
26 errors
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:125
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:58
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:91
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:115
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:119
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:123
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/publish.yml:155
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:94
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:164
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:202
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:245
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:281
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:319
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:351
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/third_party.yml:408
unpinned action reference
View on GitHub
typing-inspect==0.9.0 ilevkivskyi/typing_inspect scanned medium
4 errors 2 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:51
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:51
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:53
unpinned action reference
View on GitHub
typing-inspection==0.4.2 pydantic/typing-inspection scanned high
39 errors 16 warnings 1 note
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:20
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:92
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:112
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:169
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:217
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:15
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:47
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:82
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:107
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:121
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:189
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:62
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:65
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:76
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:112
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:113
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:135
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:148
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:155
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:169
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:172
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:178
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:183
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:202
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:217
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:219
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:227
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:235
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:21
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:65
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:93
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:113
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:129
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/coverage.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/coverage.yml:33
overly broad permissions
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/coverage.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:40
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:45
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs_publish.yml:17
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/docs_publish.yml:12
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/docs_publish.yml:30
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/docs_publish.yml:31
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/docs_publish.yml:43
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs_publish.yml:17
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs_publish.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs_publish.yml:38
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/docs_publish.yml:22
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
urllib3==2.6.3 urllib3/urllib3 scanned high clean
uv==0.11.8 astral-sh/uv scanned high
2 errors 12 warnings 3 notes
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/ci.yml:155
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/ci.yml:218
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/ci.yml:246
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/ci.yml:252
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/ci.yml:265
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:18
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:105
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:209
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:261
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:361
code injection via template expansion
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:119
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:129
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:278
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:294
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:371
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:381
secrets unconditionally inherited by called workflow
View on GitHub
zizmor/secrets-inherit: zizmor/secrets-inherit
.github/workflows/release.yml:391
secrets unconditionally inherited by called workflow
View on GitHub
virtualenv==21.3.0 pypa/virtualenv scanned high clean
vulture==2.16 jendrikseipp/vulture scanned high
8 errors 2 warnings 3 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/main.yml:15
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:28
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:54
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pre-commit.yml:12
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/pre-commit.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pre-commit.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pre-commit.yml:13
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:19
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/release.yml:19
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
watchdog==6.0.0 gorakhargosh/watchdog scanned high
15 errors 8 warnings 6 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-and-publish.yml:43
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-and-publish.yml:69
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-and-publish.yml:97
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-and-publish.yml:16
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-and-publish.yml:38
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-and-publish.yml:64
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-and-publish.yml:92
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-and-publish.yml:115
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/build-and-publish.yml:133
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:59
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:70
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:102
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:110
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-and-publish.yml:133
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:76
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:15
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:37
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:77
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:80
unpinned action reference
View on GitHub
wcwidth==0.7.0 jquast/wcwidth scanned high
24 errors 4 warnings 7 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:80
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:139
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:1
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:21
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:59
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci.yml:133
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yml:116
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci.yml:122
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:48
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:82
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:126
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:139
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:140
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:146
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:154
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:170
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:182
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:48
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:82
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/ci.yml:140
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:26
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/codeql.yml:30
action has a known vulnerability
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/codeql.yml:36
action has a known vulnerability
View on GitHub
zizmor/known-vulnerable-actions: zizmor/known-vulnerable-actions
.github/workflows/codeql.yml:39
action has a known vulnerability
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:39
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codspeed.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:21
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codspeed.yml:32
unpinned action reference
View on GitHub
yamlfix==1.19.1 lyz-code/yamlfix scanned high
9 errors 9 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/build.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build.yml:29
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build.yml:47
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/install.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/install.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/install.yml:16
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/install.yml:18
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/tests.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:2
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:12
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tests.yml:52
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:19
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tests.yml:21
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/update.yml:9
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/update.yml:12
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/update.yml:17
unpinned action reference
View on GitHub
yarl==1.23.0 aio-libs/yarl scanned medium
47 errors 13 warnings 17 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/aiohttp.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/aiohttp.yml:44
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/aiohttp.yml:30
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/aiohttp.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/aiohttp.yml:45
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/aiohttp.yml:49
unpinned action reference
View on GitHub
zizmor/cache-poisoning: zizmor/cache-poisoning
.github/workflows/aiohttp.yml:49
runtime artifacts potentially vulnerable to a cache poisoning attack
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/auto-merge.yml:4
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/auto-merge.yml:18
unpinned action reference
View on GitHub
zizmor/bot-conditions: zizmor/bot-conditions
.github/workflows/auto-merge.yml:14
spoofable bot actor check
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:77
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci-cd.yml:236
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:3
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:46
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:65
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:127
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:130
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:198
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:389
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:406
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:425
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:444
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:456
overly broad permissions
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ci-cd.yml:468
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:105
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:109
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/ci-cd.yml:313
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:78
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:114
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:237
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:239
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:246
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:254
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:264
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:269
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:352
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:377
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:438
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:452
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:541
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:549
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:560
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:574
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:577
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci-cd.yml:587
unpinned action reference
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:132
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:391
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:408
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/obfuscation: zizmor/obfuscation
.github/workflows/ci-cd.yml:470
obfuscated usage of GitHub Actions features
View on GitHub
zizmor/superfluous-actions: zizmor/superfluous-actions
.github/workflows/ci-cd.yml:587
action functionality is already included by the runner
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/codeql.yml:32
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:36
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/codeql.yml:45
unpinned action reference
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-cibuildwheel.yml:88
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:111
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-cibuildwheel.yml:117
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/reusable-codspeed.yml:77
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/reusable-codspeed.yml:160
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:80
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:100
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:109
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-codspeed.yml:170
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/reusable-linters.yml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:46
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/reusable-linters.yml:66
unpinned action reference
View on GitHub
z3-solver==4.16.0.0 Z3Prover/z3 scanned medium
405 errors 15 warnings 117 notes
zizmor/artipacked: zizmor/artipacked
.github/workflows/Windows.yml:30
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/Windows.yml:14
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/Windows.yml:31
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/Windows.yml:33
unpinned action reference
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/Windows.yml:44
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/Windows.yml:50
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/Windows.yml:68
usage of GitHub Actions misfeatures
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/a3-python.lock.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/a3-python.lock.yml:338
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/a3-python.lock.yml:912
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/a3-python.lock.yml:1051
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/a3-python.lock.yml:1258
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/academic-citation-tracker.lock.yml:321
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:346
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:942
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:1080
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:1285
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/academic-citation-tracker.lock.yml:1358
unpinned action reference
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/agentics-maintenance.yml:197
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/agentics-maintenance.yml:282
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:133
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:162
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:177
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:207
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:253
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:297
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:312
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:343
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:358
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:440
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:477
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/agentics-maintenance.yml:492
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/android-build.yml:24
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/android-build.yml:25
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/android-build.yml:36
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/api-coherence-checker.lock.yml:322
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:347
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:943
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:1080
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:1285
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/api-coherence-checker.lock.yml:1358
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/build-warning-fixer.lock.yml:312
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-warning-fixer.lock.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-warning-fixer.lock.yml:337
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-warning-fixer.lock.yml:920
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-warning-fixer.lock.yml:1057
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-warning-fixer.lock.yml:1264
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/build-z3-cache.yml:31
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/build-z3-cache.yml:73
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-z3-cache.yml:32
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-z3-cache.yml:35
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/build-z3-cache.yml:48
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:40
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:83
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:123
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:167
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:222
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:316
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:406
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:455
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:496
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ci.yml:516
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:44
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:168
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:171
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:223
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:226
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:317
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:320
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:328
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:334
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:407
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:410
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:456
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:459
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:497
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:500
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:517
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ci.yml:520
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/code-conventions-analyzer.lock.yml:317
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:342
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:991
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:1129
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:1336
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-conventions-analyzer.lock.yml:1409
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:94
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:350
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:933
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:1084
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:1266
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/code-simplifier.lock.yml:1337
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/coverage.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/coverage.yml:85
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:22
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/coverage.yml:98
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/cross-build.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/cross-build.yml:23
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/csa-analysis.lock.yml:322
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:347
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:943
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:1081
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:1286
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/csa-analysis.lock.yml:1359
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/docs.yml:48
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:52
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:97
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:128
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/docs.yml:134
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/issue-backlog-processor.lock.yml:322
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:347
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:966
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:1103
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:1311
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/issue-backlog-processor.lock.yml:1384
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:375
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:972
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:1110
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:1292
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:1345
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety-report.lock.yml:1418
unpinned action reference
View on GitHub
zizmor/github-env: zizmor/github-env
.github/workflows/memory-safety-report.lock.yml:1371
dangerous use of environment file
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/memory-safety.yml:33
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/memory-safety.yml:123
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/memory-safety.yml:222
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:34
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:124
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:197
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/memory-safety.yml:213
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/msvc-static-build-clang-cl.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/msvc-static-build-clang-cl.yml:17
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/msvc-static-build.yml:16
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/msvc-static-build.yml:17
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:29
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:89
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:144
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:199
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:258
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:294
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:330
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:363
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:396
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:433
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:472
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:512
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:555
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:584
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:613
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:642
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:674
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:729
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:781
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly-validation.yml:837
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/dangerous-triggers: zizmor/dangerous-triggers
.github/workflows/nightly-validation.yml:3
use of fundamentally insecure workflow trigger
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:42
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:101
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:156
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:211
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:266
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:302
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:337
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:370
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:403
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:445
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:485
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:524
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:567
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:596
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:625
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:655
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:686
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:736
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly-validation.yml:788
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:30
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:93
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:145
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:148
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:200
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:203
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:259
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:295
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:331
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:364
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:397
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:434
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:437
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:473
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:476
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:513
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:516
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:556
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:559
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:585
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:588
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:614
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:617
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:643
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:646
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:675
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:678
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:730
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:782
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:838
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly-validation.yml:841
unpinned action reference
View on GitHub
zizmor/github-env: zizmor/github-env
.github/workflows/nightly-validation.yml:743
dangerous use of environment file
View on GitHub
zizmor/github-env: zizmor/github-env
.github/workflows/nightly-validation.yml:795
dangerous use of environment file
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:37
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:60
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:88
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:136
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:183
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:212
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:247
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:303
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:341
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:389
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:443
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:469
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:495
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:525
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:600
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:645
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nightly.yml:760
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/nightly.yml:20
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly.yml:578
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nightly.yml:623
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:38
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:41
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:49
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:64
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:72
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:92
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:137
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:140
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:184
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:187
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:201
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:213
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:216
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:236
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:248
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:251
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:291
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:304
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:329
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:342
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:377
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:390
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:432
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:444
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:447
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:458
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:470
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:473
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:484
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:496
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:499
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:510
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:526
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:529
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:534
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:540
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:546
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:552
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:558
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:564
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:570
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:587
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:601
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:604
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:609
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:615
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:632
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:646
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:649
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:654
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:660
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:666
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:672
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:678
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:684
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:690
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:696
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:731
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:761
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:764
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:829
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nightly.yml:835
unpinned action reference
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:452
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:478
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:504
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:575
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:581
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:620
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nightly.yml:626
usage of GitHub Actions misfeatures
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:46
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:70
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:94
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:115
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:136
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:159
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/nuget-build.yml:214
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/nuget-build.yml:15
overly broad permissions
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:34
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:58
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:82
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:192
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:192
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:241
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/nuget-build.yml:241
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:26
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:37
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:47
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:50
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:61
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:74
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:85
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:95
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:98
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:106
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:116
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:119
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:127
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:137
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:140
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:148
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:160
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:163
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:168
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:184
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:201
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:215
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:218
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:223
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:233
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/nuget-build.yml:250
unpinned action reference
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:31
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:55
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:79
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:189
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:195
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:238
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/nuget-build.yml:244
usage of GitHub Actions misfeatures
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/ocaml.yaml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ocaml.yaml:10
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ocaml.yaml:20
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ocaml.yaml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ocaml.yaml:33
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ocaml.yaml:41
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/ostrich-benchmark.lock.yml:309
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ostrich-benchmark.lock.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ostrich-benchmark.lock.yml:334
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ostrich-benchmark.lock.yml:905
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ostrich-benchmark.lock.yml:1042
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/ostrich-benchmark.lock.yml:1247
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/pyodide.yml:22
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyodide.yml:23
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/pyodide.yml:63
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/qf-s-benchmark.lock.yml:313
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/qf-s-benchmark.lock.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/qf-s-benchmark.lock.yml:338
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/qf-s-benchmark.lock.yml:909
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/qf-s-benchmark.lock.yml:1046
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/qf-s-benchmark.lock.yml:1251
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release-notes-updater.lock.yml:313
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-notes-updater.lock.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-notes-updater.lock.yml:338
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-notes-updater.lock.yml:908
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-notes-updater.lock.yml:1044
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release-notes-updater.lock.yml:1249
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:38
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:67
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:98
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:146
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:193
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:222
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:257
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:313
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:351
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:399
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:453
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:479
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:505
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:535
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:610
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:655
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:768
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/release.yml:824
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/release.yml:23
overly broad permissions
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/release.yml:848
prefer trusted publishing for authentication
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:588
code injection via template expansion
View on GitHub
zizmor/template-injection: zizmor/template-injection
.github/workflows/release.yml:633
code injection via template expansion
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:39
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:42
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:56
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:68
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:71
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:82
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:99
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:102
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:147
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:150
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:194
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:197
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:211
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:223
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:226
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:246
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:258
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:261
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:301
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:314
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:339
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:352
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:387
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:400
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:442
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:454
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:457
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:468
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:480
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:483
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:494
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:506
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:509
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:520
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:536
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:539
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:544
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:550
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:556
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:562
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:568
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:574
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:580
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:597
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:611
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:614
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:619
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:625
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:642
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:656
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:659
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:664
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:670
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:676
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:682
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:688
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:694
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:700
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:706
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:738
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:769
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:772
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:825
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:828
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:834
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:840
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:861
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/release.yml:867
unpinned action reference
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:462
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:488
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:514
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:585
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:591
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:630
usage of GitHub Actions misfeatures
View on GitHub
zizmor/misfeature: zizmor/misfeature
.github/workflows/release.yml:636
usage of GitHub Actions misfeatures
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/specbot-crash-analyzer.lock.yml:321
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:344
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:982
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:1120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:1325
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/specbot-crash-analyzer.lock.yml:1398
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:346
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:948
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:1083
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:1289
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tactic-to-simplifier.lock.yml:1362
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/tptp-benchmark.lock.yml:317
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tptp-benchmark.lock.yml:87
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tptp-benchmark.lock.yml:342
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tptp-benchmark.lock.yml:923
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tptp-benchmark.lock.yml:1060
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/tptp-benchmark.lock.yml:1266
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wasm-release.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/use-trusted-publishing: zizmor/use-trusted-publishing
.github/workflows/wasm-release.yml:64
prefer trusted publishing for authentication
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm-release.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm-release.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm-release.yml:39
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wasm.yml:23
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm.yml:24
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm.yml:27
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wasm.yml:32
unpinned action reference
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/wip.yml:19
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/wip.yml:19
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/workflow-suggestion-agent.lock.yml:322
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:90
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:347
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:943
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:1080
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:1285
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/workflow-suggestion-agent.lock.yml:1358
unpinned action reference
View on GitHub
zizmor/excessive-permissions: zizmor/excessive-permissions
.github/workflows/zipt-code-reviewer.lock.yml:318
overly broad permissions
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:89
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:343
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:967
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:1103
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:1309
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/zipt-code-reviewer.lock.yml:1382
unpinned action reference
View on GitHub
zipp==3.23.1 jaraco/zipp scanned high
7 errors 3 warnings
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:57
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:84
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/artipacked: zizmor/artipacked
.github/workflows/main.yml:120
credential persistence through GitHub Actions artifacts
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:57
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:66
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:84
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:88
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:107
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:120
unpinned action reference
View on GitHub
zizmor/unpinned-uses: zizmor/unpinned-uses
.github/workflows/main.yml:122
unpinned action reference
View on GitHub
zizmor==1.24.1 zizmorcore/zizmor scanned high clean