You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
GitHub Actions workflow policy: can we trigger a repository scan from ASF infra ? #2575
I have double-checked the workflows (and they are being scanned by CodeQL / Security tools) and the workflow is OK and complies with all security policy.
We should check all our workflows especially the
labelerto ensure correct and secure use.refs apache/sedona#2645
https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=321719166#GitHubActionsSecurity-Buildstriggeredwithpull_request_target
https://github.com/apache/shiro/blob/main/.github/workflows/labeler.yml