Some more hardening to not process raw jinja inside salt/ansible cmd. But, I think this is the end of the road
build-deb.yml #720 -Commit
d96ad3dc02
pushed by
mig5
Ensure that diff also runs through validate()
build-deb.yml #705 -Commit
cec6023a40
pushed by
mig5
Add warning about --dangerous mode if sops is not in use
lint.yml #704 -Commit
a1d7a9e4e6
pushed by
mig5
Add warning about --dangerous mode if sops is not in use
ci.yml #703 -Commit
a1d7a9e4e6
pushed by
mig5
Add warning about --dangerous mode if sops is not in use
build-deb.yml #702 -Commit
a1d7a9e4e6
pushed by
mig5
Avoid TOCTOU issues, stronger perms on manifest dir, don't allow harvesting to existing dir by default, scan whole file for potential secrets
build-deb.yml #699 -Commit
e78f61c5ed
pushed by
mig5
Fix the almalinux tests - skip jinjaturtle and systemd in CI
lint.yml #689 -Commit
6ee8c60e64
pushed by
mig5