Skip to content

Report fix - #45920

Closed
Analyzesa wants to merge 8 commits into
github:mainfrom
Analyzesa:report-fix
Closed

Analyzesa wants to merge 8 commits into
github:mainfrom
Analyzesa:report-fix

Conversation

@Analyzesa

Copy link
Copy Markdown

Why:

This PR adds draft security report files related to a potential CI supply-chain hardening concern in the GitHub Actions Node.js documentation examples.

Closes: N/A

What's being changed (if available, include any code snippets, screenshots, or gifs):

This PR adds:

  • report_full.txt
  • report_short.txt
  • reports.zip

These files contain full and short draft reports describing the issue, proof of concept, and impact.

Check off the following:

  • A subject matter expert (SME) has reviewed the technical accuracy of the content in this PR. In most cases, the author can be the SME. Open source contributions may require an SME review from GitHub staff.
  • The changes in this PR meet the docs fundamentals that are required for all content.
  • All CI checks are passing and the changes look good in the review environment.

@github-actions github-actions Bot added the triage Do not begin working on this issue until triaged by the team label Sep 16, 2026
@docs-bot docs-bot added the invalid This issue/PR is invalid label Sep 16, 2026
@docs-bot

Copy link
Copy Markdown
Collaborator

👋 Hi there! It looks like you've modified some files that we can't accept as contributions:

  • .github/workflows/moda-ci.yaml
  • report_full.txt
  • report_short.txt
  • reports.zip

You'll need to raise a new PR that doesn't include those files, before we can review.

The complete list of files we can't accept are:

  • Anything in the root directory
  • .devcontainer/**
  • .github/**
  • data/reusables/rai/**
  • .vscode/**
  • config/**
  • contributing/**
  • src/**
  • patches/**
  • content/actions/how-tos/secure-your-work/security-harden-deployments/**

We also can't accept contributions to files in the content directory with frontmatter contentType: rai. You can always check out our full contribution guidelines.

@github-actions

Copy link
Copy Markdown
Contributor

How to review these changes 👓

Thank you for your contribution. To review these changes, choose one of the following options:

A Hubber will need to deploy your changes internally to review.

Table of review links

Note: Please update the URL for your staging server or codespace.

This pull request contains code changes, so we will not generate a table of review links.

🤖 This comment is automatically generated.

@github-actions github-actions Bot closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

invalid This issue/PR is invalid triage Do not begin working on this issue until triaged by the team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants