Commit b3df62b
authored
The new action is broken for `separator`, which is blocking
#2757.
We will find a minimum reproduction & file an issue with their
repository.
## Security analysis
We had landed #2757 out of
an abundance-of-caution to address
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised#stepsecurity-harden-runner.
The security team wanted us to be using the latest version of the
action.
However, it was not actually necessary to land
#2757 because the prior
commit we pinned to was not compromised. There is no known CVE with the
old pinned commit.
While it's generally a good idea to use the latest version of deps, it
is not strictly necessary and in this case it is blocking us from
merging to main.
1 parent 651dbe9 commit b3df62b
File tree
3 files changed
+3
-3
lines changed- .github/workflows
3 files changed
+3
-3
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | | - | |
| 54 | + | |
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
0 commit comments