-
Notifications
You must be signed in to change notification settings - Fork 1
Improve library discovery and add CI checks #8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,17 @@ | ||||||||||
| name: Verify | ||||||||||
|
|
||||||||||
| on: | ||||||||||
| push: | ||||||||||
| pull_request: | ||||||||||
|
|
||||||||||
| jobs: | ||||||||||
| check: | ||||||||||
| runs-on: ubuntu-latest | ||||||||||
| steps: | ||||||||||
| - uses: actions/checkout@v4 | ||||||||||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: set -eu
printf '%s\n' '--- reviewed workflow ---'
git show 7c12dfcceb664ade48fd286a06110bcb050b23da:.github/workflows/ci.yml | cat -n
printf '%s\n' '--- workflow diff from merge base ---'
git diff --unified=20 5f031c35ef4692da6628c861bdbb59f00c7a1191 7c12dfcceb664ade48fd286a06110bcb050b23da -- .github/workflows/ci.yml
printf '%s\n' '--- relevant package metadata ---'
git show 7c12dfcceb664ade48fd286a06110bcb050b23da:package.json | sed -n '1,40p'Repository: screen-gd/Col Length of output: 2067 Sensitive Data Exposure Reachability: External Keep checkout credentials out of install scripts.
Disable credential persistence - uses: actions/checkout@v4
+ with:
+ persist-credentials: false📝 Committable suggestion
Suggested change
🧰 Tools🪛 zizmor (1.30.0)[warning] 11-11: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [warning] 1-18: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [warning] 8-18: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block (excessive-permissions) [error] 11-11: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||||||||||
| - uses: actions/setup-node@v4 | ||||||||||
| with: | ||||||||||
| node-version: '20.9' | ||||||||||
| cache: npm | ||||||||||
| - run: npm ci | ||||||||||
| - run: npm run check | ||||||||||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,15 +1,19 @@ | ||
| import { DirectoryExplorer } from "@/components/DirectoryExplorer"; | ||
| import { Header } from "@/components/Header"; | ||
| import { SiteFooter } from "@/components/SiteFooter"; | ||
| import { firstQuery } from "@/lib/directory"; | ||
|
|
||
| export default async function LibrariesPage({ searchParams }: { searchParams: Promise<{ q?: string }> }) { | ||
| const { q = "" } = await searchParams; | ||
| export default async function LibrariesPage({ searchParams }: { searchParams: Promise<{ q?: string | string[] }> }) { | ||
| const { q } = await searchParams; | ||
| const initialQuery = firstQuery(q); | ||
|
|
||
| return ( | ||
| <> | ||
| <Header /> | ||
| <main className="w-full max-w-full overflow-x-hidden"> | ||
| <DirectoryExplorer initialQuery={q} /> | ||
| <DirectoryExplorer initialQuery={initialQuery} /> | ||
| </main> | ||
| <SiteFooter /> | ||
| </> | ||
| ); | ||
| } |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: screen-gd/Col
Length of output: 1137
Security Misconfiguration
Reachability: External
Exploitability: Difficult
CWE: CWE-269 — Improper Privilege Management
Set read-only token permissions for the
checkjob.The job runs
npm ciafter checkout. Without an explicit permissions block, push runs use the repository or organization defaults. If those defaults grant write access, an install script could use the persisted checkout token to modify the repository.Set the job permission
📝 Committable suggestion
🧰 Tools
🪛 zizmor (1.30.0)
[warning] 1-18: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 8-18: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[info] 8-8: workflow or action definition without a name (anonymous-definition): this job
(anonymous-definition)
🤖 Prompt for AI Agents
Source: Linters/SAST tools