use v2 for gitleaks-action artifact in gh workflow #55
Annotations
4 errors and 1 warning
Ensure 3rd party workflows have SHA pinned
actions/upload-pages-artifact@v3 is not pinned to a full length commit SHA.
|
Ensure 3rd party workflows have SHA pinned
actions/checkout@v4 is not pinned to a full length commit SHA.
|
Ensure 3rd party workflows have SHA pinned
gitleaks/gitleaks-action@v2 is not pinned to a full length commit SHA.
|
Ensure 3rd party workflows have SHA pinned
At least one workflow contains an unpinned GitHub Action version.
|
Ensure 3rd party workflows have SHA pinned
The "security-checks" job of the "on-push.yml" workflow does not contain uses or steps.
|
Loading