Skip to content

feat: enable pullRequestTargetMustNotCheckoutHead and unverified scri…#66

Merged
Kirskov merged 1 commit into
mainfrom
feat/modify_plumber_configuration
Jun 11, 2026
Merged

feat: enable pullRequestTargetMustNotCheckoutHead and unverified scri…#66
Kirskov merged 1 commit into
mainfrom
feat/modify_plumber_configuration

Conversation

@Kirskov

@Kirskov Kirskov commented Jun 11, 2026

Copy link
Copy Markdown
Owner

…pts controls

Add pullRequestTargetMustNotCheckoutHead to catch CVE-2025-30066 class attacks, pipelineMustNotExecuteUnverifiedScripts to detect pipe-to-shell patterns, and pipelineMustNotLeakSecretsInConfig as an opt-in gitleaks-backed control.

…pts controls

Add pullRequestTargetMustNotCheckoutHead to catch CVE-2025-30066 class attacks,
pipelineMustNotExecuteUnverifiedScripts to detect pipe-to-shell patterns, and
pipelineMustNotLeakSecretsInConfig as an opt-in gitleaks-backed control.

Signed-off-by: Antoine GRICOURT <gricourtantoine@gmail.com>
@Kirskov Kirskov self-assigned this Jun 11, 2026
@Kirskov Kirskov merged commit bbf5829 into main Jun 11, 2026
10 checks passed
@Kirskov Kirskov deleted the feat/modify_plumber_configuration branch June 11, 2026 21:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant