You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi @bboilot-ledger, what do you imagine ? An alert when a commit is not pinned ? Or an alert if the commit doesn't belong to the main project ?
Did you try their action https://github.com/ossf/scorecard-action ? I think there is a rule for non pinned commits but I don't know if they can detect impostor commit.
Since it's a defensive rule I don't know if I want to add this
Hello @hugo-syn 👋
I recently came across https://openssf.org/blog/2024/08/12/mitigating-attack-vectors-in-github-workflows/
From a defensive aspect, it would be awesome to be able to detect impostor commit used in github actions using octoscan.
But this is more an indicator of compromise rather than a vulnerability. What do you think about adding this kind of rule?
The text was updated successfully, but these errors were encountered: