{"repo":"suzuki-shunsuke/ghalint","free":true,"listed":false,"github":"https://github.com/suzuki-shunsuke/ghalint","clone":"git clone https://github.com/suzuki-shunsuke/ghalint.git","description":"GitHub Actions linter","language":"Go","stars":258,"topics":["cli","github-actions","linter","oss","security"],"license":"MIT","category":"cli-tools","readme_excerpt":"ghalint Install Policies How to use Configuration GitHub Actions linter for security best practices. ghalint is a command line tool to check GitHub Actions Workflows and action.yaml for security policy compliance. :bulb: We've ported ghalint to lintnet module - https://lintnet.github.io/ - https://github.com/lintnet-modules/ghalint lintnet is a general purpose linter powered by Jsonnet. We've ported ghalint to the lintnet module, so you can migrate ghalint to lintnet! Policies 1. Workflow Policies 1. job permissions: All jobs should have permissions 1. deny read all permission: read-all permission should not be used 1. deny write all permission: write-all permission should not be used 1. deny inherit secrets: secrets: inherit should not be used 1. workflow secrets: Workflow should not set secrets to environment variables 1. job secrets: Job should not set secrets to environment variables 1. deny job container latest image: Job's container image tag should not be latest 1. action ref should be full length commit sha: action's ref should be full length commit SHA 1. github app should limit repositories: GitHub Actions issuing GitHub Access tokens from GitHub Apps should limit repositories 1. github app should limit permissions: GitHub Actions issuing GitHub Access tokens from GitHub Apps should limit permissions 1. job timeout minutes is required: All jobs should set timeout-minutes 1. checkout persist credentials should be false: actions/checkout's input persist-credentials sh","default_branch":null,"files":null,"tree":[],"storefront":"/r/suzuki-shunsuke","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/suzuki-shunsuke/ghalint/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}