You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Warnings in the secure-workflows UI about unsupported local actions:
KnownIssue-3: Action ./.github/actions/reproduce-composite is a local action. Local actions are not supported
KnownIssue-3: Action ./.github/actions/reproduce-docker-path is a local action. Local actions are not supported
The text was updated successfully, but these errors were encountered:
To give you some context, there are two scenarios where the API to fix token permissions is called:
A GitHub Actions workflow file content is provided as input. As an example, someone might paste the file in https://app.stepsecurity.io and click on Secure workflow button. In this case, we do not know the repository, so we cannot get to the local actions.
Currently support is missing to scan actions.
This can be helpful to detect and fix issues in local GitHub actions, or if I am using secure-workflows to fix issues in my github action repository.
Repository to reproduce this issue: https://github.com/stefreak/ossf-scorecard-repro-2189
Insecure actions in this repository: https://github.com/stefreak/ossf-scorecard-repro-2189/tree/main/.github/actions
Warnings in the secure-workflows UI about unsupported local actions:
The text was updated successfully, but these errors were encountered: