Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin chalk action in live Docker workflow #8806

Merged
merged 1 commit into from
Jan 16, 2025
Merged

Conversation

thc202
Copy link
Member

@thc202 thc202 commented Jan 16, 2025

Pin for later testing build times.

Pin for later testing build times.

Signed-off-by: thc202 <thc202@gmail.com>
@kingthorin
Copy link
Member

kingthorin commented Jan 16, 2025

Related: crashappsec/setup-chalk-action#16

No answer in over a month, I'm unconvinced they're actually/actively maintaining it.

Edit: We might be better off moving to GitHub attestations.

@thc202
Copy link
Member Author

thc202 commented Jan 16, 2025

Do you want me to go pick a ZAP issue that does not have an answer in years?

Note that this is not just about images, JARs are also chalked.

@kingthorin
Copy link
Member

kingthorin commented Jan 16, 2025

True, that's a more than fair point 😉 🤦‍♂️

@kingthorin kingthorin merged commit 359e9d3 into zaproxy:main Jan 16, 2025
9 of 10 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Jan 16, 2025
@psiinon
Copy link
Member

psiinon commented Jan 16, 2025

Logo
Checkmarx One – Scan Summary & Details1a7379fe-bce3-4165-b6ea-5b034eb21726

Fixed Issues (1)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
LOW Unpinned Actions Full Length Commit SHA /release-live-docker.yml: 15

@thc202 thc202 deleted the pin-chalk branch January 16, 2025 14:28
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Development

Successfully merging this pull request may close these issues.

3 participants