Replies: 2 comments
-
Making sure I understand: you're asking if If I got that right, the answer is (currently) no -- zizmor only audits the files you give it, it doesn't recurse into any references those files make. The nuance is that if you do |
Beta Was this translation helpful? Give feedback.
-
|
See #678 for some related discussion on this -- a recursive mode is something I'd like to enable in the future, but there are some unanswered questions/design considerations about how best to present findings that aren't immediately actionable (e.g. in third party repos). |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Consider a scenario where I have a workflow (A) that reuses another workflow (B). Workflow A is clean (according to zizmor) but B is not and has security issues. If I only scan A, will zizmor follow through and scan B for security issues?
Beta Was this translation helpful? Give feedback.
All reactions