Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: handle non-static env: in job steps #246

Merged
merged 2 commits into from
Dec 8, 2024
Merged

fix: handle non-static env: in job steps #246

merged 2 commits into from
Dec 8, 2024

Conversation

woodruffw
Copy link
Owner

See woodruffw/github-actions-models#21.

There are certainly other places where the env: can be non-static, but this gets us started.

The only place where this currently affects zizmor is in the insecure-commands audit -- I've refactored it so that a non-static env: produces an "auditor" persona finding.

CC @ubiratansoares for viz, since you wrote this audit 🙂

@woodruffw woodruffw added the bugfix Fixes a known bug label Dec 8, 2024
@woodruffw woodruffw self-assigned this Dec 8, 2024
@woodruffw woodruffw enabled auto-merge (squash) December 8, 2024 01:10
@woodruffw woodruffw merged commit e50f954 into main Dec 8, 2024
17 checks passed
@woodruffw woodruffw deleted the ww/bump-models branch December 8, 2024 01:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bugfix Fixes a known bug
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant