Conversation
|
Kudos, SonarCloud Quality Gate passed! |
| with: | ||
| fetch-depth: 0 | ||
| - name: 'Qodana Scan' | ||
| uses: JetBrains/qodana-action@v2023.2 |
There was a problem hiding this comment.
An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps mitigate the risk of a bad actor adding a backdoor to the action's repository, as they would need to generate a SHA-1 collision for a valid Git object payload.
Ignore this finding from third-party-action-not-pinned-to-commit-sha.
Qodana for PythonIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
|
Preview page for your plugin is ready here: |








No description provided.