You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@commons.apache.org by "step-security-bot (via GitHub)" <gi...@apache.org> on 2023/06/24 18:06:59 UTC

[GitHub] [commons-io] step-security-bot opened a new pull request, #461: [StepSecurity] ci: Harden GitHub Actions

step-security-bot opened a new pull request, #461:
URL: https://github.com/apache/commons-io/pull/461

   ## Summary
   
   This pull request is created by [Secure Repo](https://app.stepsecurity.io/securerepo) at the request of @garydgregory. Please merge the Pull Request to incorporate the requested changes. Please tag @garydgregory on your message if you have any questions related to the PR. You can also engage with the [StepSecurity](https://github.com/step-security) team by tagging @step-security-bot.
   
   
   ## Security Fixes
   
   ### Pinned Dependencies
   
   GitHub Action tags and Docker tags are mutatble. This poses a security risk. GitHub's Security Hardening guide recommends pinning actions to full length commit.
   
   - [GitHub Security Guide](https://docs.github.com/en/actions/security-guides/security-hardening-for-github-actions#using-third-party-actions)
   - [The Open Source Security Foundation (OpenSSF) Security Guide](https://github.com/ossf/scorecard/blob/main/docs/checks.md#pinned-dependencies)
   
   
   ## Feedback
   For bug reports, feature requests, and general feedback; please create an issue in [step-security/secure-repo](https://github.com/step-security/secure-repo). To create such PRs, please visit https://app.stepsecurity.io/securerepo.
   
   
   Signed-off-by: StepSecurity Bot <bo...@stepsecurity.io>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-io] codecov-commenter commented on pull request #461: [StepSecurity] ci: Harden GitHub Actions

Posted by "codecov-commenter (via GitHub)" <gi...@apache.org>.
codecov-commenter commented on PR #461:
URL: https://github.com/apache/commons-io/pull/461#issuecomment-1605675316

   ## [Codecov](https://app.codecov.io/gh/apache/commons-io/pull/461?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) Report
   > Merging [#461](https://app.codecov.io/gh/apache/commons-io/pull/461?src=pr&el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (150a1f4) into [master](https://app.codecov.io/gh/apache/commons-io/commit/d3b51407b3cbc3709d077ee43fe5c699b421edb1?el=desc&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache) (d3b5140) will **decrease** coverage by `0.12%`.
   > The diff coverage is `n/a`.
   
   ```diff
   @@             Coverage Diff              @@
   ##             master     #461      +/-   ##
   ============================================
   - Coverage     84.87%   84.76%   -0.12%     
   + Complexity     3349     3344       -5     
   ============================================
     Files           226      226              
     Lines          8048     8048              
     Branches        953      953              
   ============================================
   - Hits           6831     6822       -9     
   - Misses          969      974       +5     
   - Partials        248      252       +4     
   ```
   
   
   [see 2 files with indirect coverage changes](https://app.codecov.io/gh/apache/commons-io/pull/461/indirect-changes?src=pr&el=tree-more&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache)
   
   :mega: We’re building smart automated test selection to slash your CI/CD build times. [Learn more](https://about.codecov.io/iterative-testing/?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=apache)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


[GitHub] [commons-io] garydgregory merged pull request #461: [StepSecurity] ci: Harden GitHub Actions

Posted by "garydgregory (via GitHub)" <gi...@apache.org>.
garydgregory merged PR #461:
URL: https://github.com/apache/commons-io/pull/461


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscribe@commons.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org