Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
name: ci
on:
push:
branches: [main]
pull_request:
branches: [main]

jobs:
ci:
uses: got-feedback/.github/.github/workflows/reusable-ci.yml@main

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ”’ Security & Privacy | 🟠 Major | ⚑ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Inspect the workflow file and surrounding repository context.
git ls-files .github/workflows/ci.yml .github/workflows
printf '\n--- ci.yml ---\n'
cat -n .github/workflows/ci.yml

printf '\n--- search for reusable workflow references ---\n'
rg -n "got-feedback/.github/.github/workflows/reusable-ci.yml|uses: .*reusable-ci.yml|workflow_call|workflow_dispatch" .github/workflows . -g '!**/node_modules/**'

Repository: got-feedBack/feedBack-plugin-fretboard

Length of output: 596


Pin the reusable workflow ref.

@main is mutable, so this CI job can pick up unreviewed changes from got-feedback/.github. Pin it to a commit SHA or immutable release tag instead.

πŸ€– Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ci.yml at line 10, The reusable CI workflow reference is
currently using a mutable branch ref, which can change without review. Update
the workflow call in the CI configuration to use an immutable reference instead,
such as a specific commit SHA or release tag, so the reusable workflow remains
stable and reproducible. Locate the external workflow invocation that uses
got-feedback/.github/.github/workflows/reusable-ci.yml and replace the current
ref with a pinned one.

Loading