-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
Context
These show how symlinks in linters can go wrong:
- GHSA-g86g-chm8-7r2p
- https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md
Proposal
Do one of these two (likely they aren't compatible):
- filter out symlinks as a
strategy - create a linter that fails whenever a file is a symlink
Acceptance criteria
lein checkouts keep working
Additional resources
git config --global core.symlinks false might be a good thing to perform in CI prior to the checkout step.
Metadata
Metadata
Assignees
Labels
No labels