Skip to content

CVE-2021-32724 Found In Your GitHub Actions Workflows: check-spelling/[email protected] #205

@ziyue-pan

Description

@ziyue-pan

Hello, we are an research team focusing on open source CI/CD security.
We have detected an action containing CVE imported in your workflow configuration.

CVE Info

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32724
GHSA-g86g-chm8-7r2p

Affected Workflow

https://github.com/devonfw-tutorials/tutorials/blob/main/.github/workflows/spell-check.yml#L12

Solution

Edit the workflow to use check-spelling/[email protected] or newer version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions