Commit 6570f77
committed
fix: resolve Semgrep shell injection and zizmor warnings
- Use env var instead of inline ${{ inputs.mode }} in sync-settings
composite action to prevent shell injection (Semgrep finding)
- Add if: always() to Trivy step so it runs regardless of Semgrep
result, preventing missing SARIF upload
- Set zizmor secrets-outside-env to info level (acceptable for
single-admin personal account without GitHub Environments)1 parent b98ffb2 commit 6570f77
3 files changed
Lines changed: 4 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
36 | 36 | | |
37 | 37 | | |
38 | 38 | | |
| 39 | + | |
39 | 40 | | |
40 | | - | |
| 41 | + | |
41 | 42 | | |
42 | 43 | | |
43 | 44 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
0 commit comments