fix: block unsafe privileged workflow checkouts

This commit is contained in:
Affaan Mustafa
2026-04-12 23:23:01 -07:00
parent a2ad68e7e6
commit 3792b69a38
4 changed files with 235 additions and 0 deletions

View File

@@ -190,6 +190,10 @@ jobs:
run: node scripts/ci/validate-install-manifests.js
continue-on-error: false
- name: Validate workflow security
run: node scripts/ci/validate-workflow-security.js
continue-on-error: false
- name: Validate rules
run: node scripts/ci/validate-rules.js
continue-on-error: false

View File

@@ -42,6 +42,9 @@ jobs:
- name: Validate install manifests
run: node scripts/ci/validate-install-manifests.js
- name: Validate workflow security
run: node scripts/ci/validate-workflow-security.js
- name: Validate rules
run: node scripts/ci/validate-rules.js