Skip to content

[oblt-aw][security] SEC-030 — findings (2026-05-09) #830

@elastic-vault-github-plugin-prod

Description

Security findings (SEC-030)

Analysis date: 2026-05-09
Occurrences: 54

Details

  1. .github/workflows/ci.yml — line 29medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  2. .github/workflows/ci.yml — line 41medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  3. .github/workflows/ci.yml — line 44medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  4. .github/workflows/ci.yml — line 49medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  5. .github/workflows/ci.yml — line 70medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  6. .github/workflows/ci.yml — line 73medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  7. .github/workflows/ci.yml — line 95medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  8. .github/workflows/ci.yml — line 126medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  9. .github/workflows/distribute-client-workflow.yml — line 37medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  10. .github/workflows/distribute-client-workflow.yml — line 44medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  11. .github/workflows/distribute-client-workflow.yml — line 51medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  12. .github/workflows/distribute-client-workflow.yml — line 95medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  13. .github/workflows/distribute-client-workflow.yml — line 101medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  14. .github/workflows/distribute-client-workflow.yml — line 106medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  15. .github/workflows/distribute-client-workflow.yml — line 197medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  16. .github/workflows/distribute-client-workflow.yml — line 209medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  17. .github/workflows/distribute-client-workflow.yml — line 212medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  18. .github/workflows/get-enabled-workflows.yml — line 32medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  19. .github/workflows/get-enabled-workflows.yml — line 45medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  20. .github/workflows/gh-aw-agent-suggestions.yml — line 16medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  21. .github/workflows/gh-aw-autodoc.yml — line 18medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  22. .github/workflows/gh-aw-autodoc.yml — line 52medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  23. .github/workflows/gh-aw-automerge.yml — line 29medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  24. .github/workflows/gh-aw-automerge.yml — line 37medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  25. .github/workflows/gh-aw-automerge.yml — line 49medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  26. .github/workflows/gh-aw-automerge.yml — line 74medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  27. .github/workflows/gh-aw-automerge.yml — line 140medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  28. .github/workflows/gh-aw-dependency-review.yml — line 24medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  29. .github/workflows/gh-aw-dependency-review.yml — line 74medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  30. .github/workflows/gh-aw-dependency-review.yml — line 77medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  31. .github/workflows/gh-aw-duplicate-issue-detector.yml — line 17medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  32. .github/workflows/gh-aw-issue-fixer.yml — line 22medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  33. .github/workflows/gh-aw-issue-triage.yml — line 18medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  34. .github/workflows/gh-aw-mention-in-issue.yml — line 20medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  35. .github/workflows/gh-aw-resource-not-accessible-by-integration-detector.yml — line 36medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  36. .github/workflows/gh-aw-resource-not-accessible-by-integration-fixer.yml — line 22medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  37. .github/workflows/gh-aw-resource-not-accessible-by-integration-triage.yml — line 27medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  38. .github/workflows/gh-aw-resource-not-accessible-by-integration-triage.yml — line 232medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  39. .github/workflows/gh-aw-resource-not-accessible-by-integration-triage.yml — line 235medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  40. .github/workflows/gh-aw-security-detector.yml — line 19medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  41. .github/workflows/gh-aw-security-detector.yml — line 25medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  42. .github/workflows/gh-aw-security-detector.yml — line 36medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  43. .github/workflows/gh-aw-security-detector.yml — line 51medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  44. .github/workflows/gh-aw-security-fixer.yml — line 22medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses) | zizmor [secrets-inherit]: secrets unconditionally inherited by called workflow (https://docs.zizmor.sh/audits/#secrets-inherit)

  45. .github/workflows/gh-aw-security-triage.yml — line 26medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  46. .github/workflows/gh-aw-security-triage.yml — line 121medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  47. .github/workflows/gh-aw-security-triage.yml — line 124medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  48. .github/workflows/load-allowed-authors.yml — line 37medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  49. .github/workflows/oblt-aw.yml — line 27medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  50. .github/workflows/sync-control-plane-dashboard.yml — line 30medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  51. .github/workflows/sync-control-plane-dashboard.yml — line 33medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  52. .github/workflows/sync-control-plane-dashboard.yml — line 65medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  53. .github/workflows/sync-control-plane-dashboard.yml — line 69medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)

  54. .github/workflows/sync-control-plane-dashboard.yml — line 74medium — zizmor [unpinned-uses]: unpinned action reference (https://docs.zizmor.sh/audits/#unpinned-uses)


Generated by oblt-aw security detector. Rules: security-scanning-ruleset (SEC-001–SEC-044, aligned with observability-robots#3758).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions