Skip to content

Update README.md#1031

Open
cx-anurag-dalke wants to merge 5 commits into
mainfrom
other/test_branch
Open

Update README.md#1031
cx-anurag-dalke wants to merge 5 commits into
mainfrom
other/test_branch

Conversation

@cx-anurag-dalke

Copy link
Copy Markdown
Contributor

Upated x logo image icon

Upated x logo image icon
- Pin internal workflow references to specific commit hashes
- Replace secrets: inherit with explicit secret mappings
- Add concurrency limits to all workflows to prevent overlapping runs
- Add descriptive job names for better CI/CD visibility
- Add explanatory comments for all permission blocks
- Add explicit permissions block to cx-one-scan workflow
- Improve overall security posture of GitHub Actions workflows

All zizmor security audits now pass with zero findings.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 47
  • secrets.CX_CLIENT_ID at line 72
  • secrets.CX_CLIENT_SECRET at line 73
  • secrets.CX_BASE_URI at line 74
  • secrets.CX_TENANT at line 75
  • secrets.CX_APIKEY at line 76

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-atish-jadhav) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@stepsecurity-app

Copy link
Copy Markdown
Contributor

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.AST_RND_SCANS_BASE_URI at line 33
  • secrets.AST_RND_SCANS_TENANT at line 34
  • secrets.AST_RND_SCANS_CLIENT_ID at line 35
  • secrets.AST_RND_SCANS_CLIENT_SECRET at line 36

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-atish-jadhav) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

Add comment directive to suppress zizmor linting warning about anonymous job definition in the integration-tests CI workflow job.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants