scorecard/.github/workflows
Spencer Schrock 84bd607ae8
🌱 fix script injection (#3695)
Thanks to @AdnaneKhan for the report.

* start with reporter patch
* use env variable for bash step too

Signed-off-by: Spencer Schrock <sschrock@google.com>

---------

Signed-off-by: Spencer Schrock <sschrock@google.com>
2023-11-27 23:10:51 +00:00
..
codeql-analysis.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
depsreview.yml 🌱 Bump github.com/sigstore/cosign/v2 from 2.1.1 to 2.2.1 in /tools (#3660) 2023-11-13 10:58:51 -08:00
docker.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
gitlab.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
goreleaser.yaml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
integration.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
lint.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
main.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
publishimage.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
scdiff.yml 🌱 fix script injection (#3695) 2023-11-27 23:10:51 +00:00
scorecard-analysis.yml 🌱 Bump ossf/scorecard-action from 2.3.0 to 2.3.1 (#3599) 2023-10-27 23:44:15 +00:00
slsa-goreleaser.yml 🌱 Bump slsa-framework/slsa-verifier from 2.4.0 to 2.4.1 (#3652) 2023-11-09 01:34:39 +00:00
stale.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00
verify.yml 🌱 Bump the github-actions group with 2 updates (#3686) 2023-11-20 12:16:39 -05:00