noamd-legit
noamd-legit
### TL;DR Add SARIF as an additional output format ### Detailed design _No response_ ### Additional information _No response_
### TL;DR Support scanning GHES for misconfigurations ### Detailed design _No response_ ### Additional information _No response_
### TL;DR Add a policy that alerts if the GitHub Actions default permission is not read-only. Applies for repository & organization ### Detailed design _No response_ ### Additional information _No...
### TL;DR Currently, it is not possible to use the action with the automatically generated GITHUB_TOKEN because it has no permission to execute the following API: ``` https://api.github.com/user/orgs ``` It...
**RE: ID Numbers** When referencing, it is much easier to reference a number, like `GH-1`, than a name. It also allows the policy name to change without breaking other references...
#### What's being changed? #### Is this PR related to an existing issue? #### Check off the following: - [ ] This PR follows the CONTRIBUTION.md guidelines - [ ]...