Secrets outside of environments #181
Replies: 2 comments 1 reply
-
Hi @AndrewMohawk, thanks for the kind words! I'm glad you're enjoying the tool. Could you say a bit more about the audit idea here? Is the idea that this would be an online audit over the I think that makes sense to me, but it might be outside of |
Beta Was this translation helpful? Give feedback.
-
This is a new audit idea, so I've created #184 to track it. Thanks again @AndrewMohawk! |
Beta Was this translation helpful? Give feedback.
-
Loving the tool so far! I'd love to have zizmor also determine secrets referenced outside of environments within GH actions. I see it fairly often and it means that if anyone has the ability to create a PR with an updated workflow they can exfil secrets that arent tied to an environment (and that environment having branch protections). The caveat here is that an attacker would have had to submit a PR before the malicious one (usually you would see them as doing typo fixes first).
Beta Was this translation helpful? Give feedback.
All reactions