Skip to content

docs: first-screen treatment for both READMEs - #34

Merged
9t29zhmwdh-coder merged 1 commit into
mainfrom
docs/first-screen
Jul 31, 2026
Merged

docs: first-screen treatment for both READMEs#34
9t29zhmwdh-coder merged 1 commit into
mainfrom
docs/first-screen

Conversation

@9t29zhmwdh-coder

Copy link
Copy Markdown
Owner

Was

Der Einstieg zählte Schwachstellenklassen auf. Neu stehen drei konkrete Fehler mit ihrer Folge: Issue-Titel im run:-Block, pull_request_target auf ungeprüftem Code, Action auf einen Tag gepinnt.

Der Ausschlusssatz sagt ehrlich, dass ein privates Repo mit vertrauenswürdigen Beitragenden die nötige Angriffsfläche gar nicht hat.

Warum

standards/documentation.md, Abschnitt "The first screen".

Nebenwirkungen

Keine, reine Doku. Version 0.3.6 mit CHANGELOG-Eintrag.

…asses

Injection vectors, supply chain risks, excessive permissions and secret
exposure are categories. They tell a reader who already knows the field
nothing new, and a reader who does not, nothing at all.

Both READMEs now name three concrete mistakes and what each hands an attacker:
an issue title interpolated into a run block, pull_request_target on untrusted
code, an action pinned to a mutable tag.

The exclusion paragraph is honest that a private repo with trusted
contributors lacks the surface most of these findings need.

Both language versions in one commit, per documentation.md section 5.
@9t29zhmwdh-coder
9t29zhmwdh-coder merged commit d2201ca into main Jul 31, 2026
7 checks passed
@9t29zhmwdh-coder
9t29zhmwdh-coder deleted the docs/first-screen branch July 31, 2026 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant