Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix security issues flagged by GitHub CodeQL #312

Open
2 tasks
bsweger opened this issue Feb 7, 2025 · 0 comments
Open
2 tasks

Fix security issues flagged by GitHub CodeQL #312

bsweger opened this issue Feb 7, 2025 · 0 comments
Assignees

Comments

@bsweger
Copy link
Collaborator

bsweger commented Feb 7, 2025

Background

We recently enabled security scanning on the variant-nowcast-hub repo, and the initial scan flagged some things to fix: https://github.com/reichlab/variant-nowcast-hub/security/code-scanning

There are 17 alerts, but only two root causes, both of which are straightforward to fix.

Definition of done

  • All workflows have explicit permissions
  • All workflows reference third-party GitHub actions by commit hash instead of by tag
@bsweger bsweger added this to Lab Work Feb 7, 2025
@bsweger bsweger converted this from a draft issue Feb 7, 2025
@bsweger bsweger self-assigned this Feb 7, 2025
@bsweger bsweger added this to the Variant Nowcast milestone Feb 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In Progress
Development

No branches or pull requests

1 participant