Last 12 weeks · 2 commits
3 of 6 standards met
As part of hardening our github workflow, I have selected, Actions permissions, allow [OWNER], and select non-[OWNER] actions and reusable workflows. Allow actions by Marketplace verified creators. _Any action or reusable workflow that matches the specified criteria, plus those defined in a repository within [OWNER] can be used._ Learn more about allowing specific actions and reusable workflows to run. Because withastro/action@v6 is not a verified creator. See https://docs.github.com/en/apps/github-marketplace/github-marketplace-overview/applying-for-publisher-verification-for-your-organization I get the following error: [!WARNING] Error The action withastro/action@v6 is not allowed in [OWNER]/[REPOSITORY] because all actions must be from a repository owned by [OWNER], created by GitHub, or verified in the GitHub Marketplace. https://github.com/marketplace/actions/astro-deploy The requirements are: 1. Two factor authentication 2. A valid email for github to communicate to 3. A verified domain and ensure that a "Verified" badge displays on your organization's profile page. This is because I worry after the TanStack GitHub Actions cache poisoning hack. I'm no security expert, so I can not judge if this is efficient security hardening or needless complication.
Repository: withastro/action. Description: A GitHub Action that deploys your Astro project to GitHub Pages Stars: 258, Forks: 56. Latest release: v6.1.2 (1mo ago). Open PRs: 3, open issues: 5. Last activity: 1mo ago. Community health: 62%. Top contributors: natemoo-re, delucis, colinhacks, Princesseuh, ollecoffee, ThatXliner, mandar1jn, nickserv, torn4dom4n, swift502 and others.