You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@commons.apache.org by "step-security-bot (via GitHub)" <gi...@apache.org> on 2023/06/24 18:23:22 UTC

[GitHub] [commons-codec] step-security-bot opened a new pull request, #187: [StepSecurity] ci: Harden GitHub Actions

step-security-bot opened a new pull request, #187:
URL: https://github.com/apache/commons-codec/pull/187

   ## Summary
   
   This pull request is created by [Secure Repo](https://app.stepsecurity.io/securerepo) at the request of @garydgregory. Please merge the Pull Request to incorporate the requested changes. Please tag @garydgregory on your message if you have any questions related to the PR. You can also engage with the [StepSecurity](https://github.com/step-security) team by tagging @step-security-bot.
   
   
   ## Security Fixes
   
   ### Pinned Dependencies
   
   GitHub Action tags and Docker tags are mutatble. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.
   
   - [GitHub Security Guide](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions)
   - [The Open Source Security Foundation (OpenSSF) Security Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)
   
   
   ## Feedback
   For bug reports, feature requests, and general feedback; please create an issue in [step-security/secure-repo](https://github.com/step-security/secure-repo). To create such PRs, please visit https://app.stepsecurity.io/securerepo.
   
   
   Signed-off-by: StepSecurity Bot <bo...@stepsecurity.io>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-codec] garydgregory merged pull request #187: [StepSecurity] ci: Harden GitHub Actions

Posted by "garydgregory (via GitHub)" <gi...@apache.org>.
garydgregory merged PR #187:
URL: https://github.com/apache/commons-codec/pull/187


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-codec] codecov-commenter commented on pull request #187: [StepSecurity] ci: Harden GitHub Actions

Posted by "codecov-commenter (via GitHub)" <gi...@apache.org>.
codecov-commenter commented on PR #187:
URL: https://github.com/apache/commons-codec/pull/187#issuecomment-1605678192

   ## [Codecov](https://app.codecov.io/gh/apache/commons-codec/pull/187?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) Report
   > Merging [#187](https://app.codecov.io/gh/apache/commons-codec/pull/187?src=pr&el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (a8089c6) into [master](https://app.codecov.io/gh/apache/commons-codec/commit/780cc73a629b332f317f46b30b7ce2df9270daa6?el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (780cc73) will **not change** coverage.
   > The diff coverage is `n/a`.
   
   ```diff
   @@            Coverage Diff            @@
   ##             master     #187   +/-   ##
   =========================================
     Coverage     92.20%   92.20%           
     Complexity     1740     1740           
   =========================================
     Files            67       67           
     Lines          4603     4603           
     Branches        728      728           
   =========================================
     Hits           4244     4244           
     Misses          244      244           
     Partials        115      115           
   ```
   
   
   
   :mega: We’re building smart automated test selection to slash your CI/CD build times. [Learn more](https://about.codecov.io/iterative-testing/?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org