Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Add a workflow vulnerability scanner by dkfellows · Pull Request #61 · hpcflow/github-support · GitHub
Skip to content

Add a workflow vulnerability scanner - #61

Open
dkfellows wants to merge 8 commits into
mainfrom
scan
Open

Add a workflow vulnerability scanner#61
dkfellows wants to merge 8 commits into
mainfrom
scan

Conversation

@dkfellows

@dkfellowsdkfellows commented May 18, 2026

Copy link
Copy Markdown
Collaborator

This is work in progress...

This adds a workflow vulnerability scanner and fixes the issues it has found. Still to do:

  • Create scanner workflow
  • Fix issues found in reusable workflows
  • Fix issues found in actions
  • Test with hpcflow
  • Test with matflow

@dkfellowsdkfellows self-assigned this May 18, 2026
@dkfellowsdkfellows added the enhancement New feature or request label May 18, 2026
@dkfellowsdkfellows linked an issue May 18, 2026 that may be closed by this pull request
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/test-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
Comment thread.github/workflows/build-exes-impl.yml Fixed
id: linux_onefile
if: inputs.build_onefile == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
id: linux_onedir
if: inputs.build_onedir == 'true'
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Build executables within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
- name: Release
id: release
uses: softprops/action-gh-release@v3
uses: softprops/action-gh-release@b4309332981a82ec1c5618f44dd2e27cc8bfbfda # v3.0.0

- name: Run unit tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3

- name: Run integration tests within Docker
uses: addnab/docker-run-action@v3
uses: addnab/docker-run-action@4f65fabd2431ebc8d299f8e5a018d79a769ae185 # v3
This needs a little care because what is being cached is tricky
@dkfellows

Copy link
Copy Markdown
CollaboratorAuthor

All remaining issues are... arguably not problems, given that the suggested fixes make things worse in my eyes in the context of what is being done.

@dkfellows
dkfellows marked this pull request as ready for review May 18, 2026 16:06
@dkfellows
dkfellows requested a review from a team as a code ownerMay 18, 2026 16:06
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Analyse for workflow weaknesses

2 participants

@dkfellows@github-advanced-security