You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@commons.apache.org by "step-security-bot (via GitHub)" <gi...@apache.org> on 2023/06/24 21:25:46 UTC

[GitHub] [commons-text] step-security-bot opened a new pull request, #428: [StepSecurity] ci: Harden GitHub Actions

step-security-bot opened a new pull request, #428:
URL: https://github.com/apache/commons-text/pull/428

   ## Summary
   
   This pull request is created by [Secure Repo](https://app.stepsecurity.io/securerepo) at the request of @garydgregory. Please merge the Pull Request to incorporate the requested changes. Please tag @garydgregory on your message if you have any questions related to the PR. You can also engage with the [StepSecurity](https://github.com/step-security) team by tagging @step-security-bot.
   
   
   ## Security Fixes
   
   ### Pinned Dependencies
   
   GitHub Action tags and Docker tags are mutatble. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.
   
   - [GitHub Security Guide](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions)
   - [The Open Source Security Foundation (OpenSSF) Security Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)
   
   
   ## Feedback
   For bug reports, feature requests, and general feedback; please create an issue in [step-security/secure-repo](https://github.com/step-security/secure-repo). To create such PRs, please visit https://app.stepsecurity.io/securerepo.
   
   
   Signed-off-by: StepSecurity Bot <bo...@stepsecurity.io>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-text] codecov-commenter commented on pull request #428: [StepSecurity] ci: Harden GitHub Actions

Posted by "codecov-commenter (via GitHub)" <gi...@apache.org>.
codecov-commenter commented on PR #428:
URL: https://github.com/apache/commons-text/pull/428#issuecomment-1605735722

   ## [Codecov](https://app.codecov.io/gh/apache/commons-text/pull/428?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) Report
   > Merging [#428](https://app.codecov.io/gh/apache/commons-text/pull/428?src=pr&el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (26136b7) into [master](https://app.codecov.io/gh/apache/commons-text/commit/344401b4f7ed4b3a15a15b20ae4bc7fd20297cad?el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (344401b) will **not change** coverage.
   > The diff coverage is `n/a`.
   
   ```diff
   @@            Coverage Diff            @@
   ##             master     #428   +/-   ##
   =========================================
     Coverage     97.12%   97.12%           
     Complexity     2332     2332           
   =========================================
     Files            84       84           
     Lines          5780     5780           
     Branches        936      936           
   =========================================
     Hits           5614     5614           
     Misses           87       87           
     Partials         79       79           
   ```
   
   
   
   :mega: We’re building smart automated test selection to slash your CI/CD build times. [Learn more](https://about.codecov.io/iterative-testing/?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-text] garydgregory merged pull request #428: [StepSecurity] ci: Harden GitHub Actions

Posted by "garydgregory (via GitHub)" <gi...@apache.org>.
garydgregory merged PR #428:
URL: https://github.com/apache/commons-text/pull/428


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org