Skip to content

Detect and maybe reject support of tools that having obviously dangerous workflows #1631

Description

@taiki-e

I'd like to establish a criterion for accepting or rejecting tool support that requires them not to use obviously dangerous workflows.

I don’t think it’s necessary to satisfy all of zizmor’s lint rules, but if triggers like https://docs.zizmor.sh/audits/#dangerous-triggers or comments-related are existed or added later (i.e., manual reviews when adding tools don’t work), I’d like to be able to reject the addition of tool support or version updates.

Related: #488
Unlike that case, since the maintainer lacks awareness of GHA security but has no malicious intent, I don’t think this situation is as difficult as that one.

However, we should avoid using support for this action as an excuse to submit reports that have nothing to do with actual vulnerabilities like rust-lang/rust#154414, thus burdening the maintainer.

cc @jayvdb

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions