What's Changed
- feat: add new rule called 'dangerous-artefact' it's based on this research https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/
- feat: move oidc-action rule to debug rule since it's not a vulnerability
- feat: update GHSA list
- feat: also include actions/github-script in --filter-run
- chore(deps): bump github.com/google/osv-scanner from 1.9.0 to 1.9.1 by @dependabot in #14
New Contributors
- @dependabot made their first contribution in #14
Full Changelog: v0.1.2...v0.1.3