CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_CODECOV_TOKEN` on a `pull_request` trigger: This…
.github/workflows/analysis.yaml:86
CRIT
MINED125
[MINED125] GHA script injection via github.head_ref in run-step: Multi-line `run: |` bloc…
.github/workflows/nix-build-job.yaml:370
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_PLUGINS_DEPLOY_KEY` on a `pull_request` trigger:…
.github/workflows/style-check.yaml:40
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_TENZIR_API_TOKEN` on a `pull_request` trigger: T…
.github/workflows/style-check.yaml:30
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_GITHUB_APP_PRIVATE_KEY` on a `pull_request` trig…
.github/workflows/tenzir.yaml:1241
CRIT
MINED116
[MINED116] Workflow uses `secrets.TEST_PYPI_TOKEN` on a `pull_request` trigger: This work…
.github/workflows/tenzir.yaml:1220
CRIT
MINED116
[MINED116] Workflow uses `secrets.PYPI_TOKEN` on a `pull_request` trigger: This workflow …
.github/workflows/tenzir.yaml:1215
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_BOT_GITHUB_TOKEN` on a `pull_request` trigger: T…
.github/workflows/tenzir.yaml:1186
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_TENZIR_API_TOKEN` on a `pull_request` trigger: T…
.github/workflows/tenzir.yaml:1171
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_BOT_GITHUB_TOKEN` on a `pull_request` trigger: T…
.github/workflows/tenzir.yaml:1116
CRIT
MINED116
[MINED116] Workflow uses `secrets.CACHIX_TENZIR_API_TOKEN` on a `pull_request` trigger: T…
.github/workflows/tenzir.yaml:1104
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_PLUGINS_DEPLOY_KEY` on a `pull_request` trigger:…
.github/workflows/tenzir.yaml:928
CRIT
MINED116
[MINED116] Workflow uses `secrets.TS_OAUTH_SECRET` on a `pull_request` trigger: This work…
.github/workflows/tenzir.yaml:915
CRIT
MINED116
[MINED116] Workflow uses `secrets.TS_OAUTH_CLIENT_ID` on a `pull_request` trigger: This w…
.github/workflows/tenzir.yaml:914
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_GITHUB_APP_PRIVATE_KEY` on a `pull_request` trig…
.github/workflows/tenzir.yaml:734
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_AUTOBUMPER_APP_PRIVATE_KEY` on a `pull_request` …
.github/workflows/tenzir.yaml:636
CRIT
MINED116
[MINED116] Workflow uses `secrets.TENZIR_PLUGINS_DEPLOY_KEY` on a `pull_request` trigger:…
.github/workflows/tenzir.yaml:611
HIGH
MINED004
[MINED004] Weak Crypto: MD5/SHA1/DES/RC4 used for security context (not just checksums).
libtenzir/include/tenzir/community_id.h…:168
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
libtenzir/builtins/operators/to_file.cpp:36
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
libtenzir/builtins/operators/from_ftp.c…:48
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
libtenzir/builtins/operators/from_file.…:34
HIGH
MINED017
[MINED017] C System Call: system() invokes shell. command injection if any arg is dynamic.
libtenzir/builtins/operators/fields.cpp:31
HIGH
MINED017
[MINED017] C System Call: system() invokes shell. command injection if any arg is dynamic.
libtenzir/builtins/components/metrics_c…:84
HIGH
MINED017
[MINED017] C System Call: system() invokes shell. command injection if any arg is dynamic.
libtenzir/builtins/aspects/index.cpp:30
HIGH
DKR014
Dockerfile copies the entire context without .dockerignore
python/Dockerfile:28
HIGH
DKR006
Dockerfile pipes a remote script into a shell
python/Dockerfile:19
HIGH
MINED126
[MINED126] Workflow container/services image `debian:bookworm-20230227-slim` unpinned: `c…
.github/workflows/analysis.yaml:20
HIGH
MINED115
[MINED115] Action `google-github-actions/auth` pinned to mutable ref `@v2`: `uses: google…
.github/workflows/tenzir.yaml:1052
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/tenzir.yaml:1045
HIGH
MINED115
[MINED115] Action `actions/cache/save` pinned to mutable ref `@v4`: `uses: actions/cache/…
.github/workflows/tenzir.yaml:1019
HIGH
MINED115
[MINED115] Action `actions/cache/restore` pinned to mutable ref `@v4`: `uses: actions/cac…
.github/workflows/tenzir.yaml:971
HIGH
MINED115
[MINED115] Action `cachix/install-nix-action` pinned to mutable ref `@v30`: `uses: cachix…
.github/workflows/tenzir.yaml:960
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/tenzir.yaml:956
HIGH
MINED115
[MINED115] Action `webfactory/ssh-agent` pinned to mutable ref `@v0.9.0`: `uses: webfacto…
.github/workflows/tenzir.yaml:926
HIGH
MINED115
[MINED115] Action `tailscale/github-action` pinned to mutable ref `@v3`: `uses: tailscale…
.github/workflows/tenzir.yaml:912
HIGH
MINED115
[MINED115] Action `actions/create-github-app-token` pinned to mutable ref `@v1`: `uses: a…
.github/workflows/tenzir.yaml:731
HIGH
MINED115
[MINED115] Action `actions/create-github-app-token` pinned to mutable ref `@v1`: `uses: a…
.github/workflows/tenzir.yaml:633
HIGH
MINED115
[MINED115] Action `webfactory/ssh-agent` pinned to mutable ref `@v0.9.0`: `uses: webfacto…
.github/workflows/tenzir.yaml:609
HIGH
MINED115
[MINED115] Action `google-github-actions/setup-gcloud` pinned to mutable ref `@v2`: `uses…
.github/workflows/tenzir.yaml:170
HIGH
MINED115
[MINED115] Action `google-github-actions/auth` pinned to mutable ref `@v2`: `uses: google…
.github/workflows/tenzir.yaml:165
HIGH
MINED115
[MINED115] Action `rlespinasse/github-slug-action` pinned to mutable ref `@v5`: `uses: rl…
.github/workflows/tenzir.yaml:163
HIGH
MINED115
[MINED115] Action `cachix/install-nix-action` pinned to mutable ref `@v30`: `uses: cachix…
.github/workflows/bump-plugins-submodul…:42
HIGH
MINED115
[MINED115] Action `crazy-max/ghaction-import-gpg` pinned to mutable ref `@v6`: `uses: cra…
.github/workflows/bump-plugins-submodul…:36
HIGH
MINED115
[MINED115] Action `actions/create-github-app-token` pinned to mutable ref `@v1`: `uses: a…
.github/workflows/bump-plugins-submodul…:31
HIGH
MINED115
[MINED115] Action `webfactory/ssh-agent` pinned to mutable ref `@v0.9.0`: `uses: webfacto…
.github/workflows/bump-plugins-submodul…:20
HIGH
MINED115
[MINED115] Action `cloudflare/wrangler-action` pinned to mutable ref `@v3`: `uses: cloudf…
.github/workflows/ccache-r2-broker.yaml:61
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/ccache-r2-broker.yaml:23
HIGH
MINED115
[MINED115] Action `aws-actions/amazon-ecr-login` pinned to mutable ref `@v2`: `uses: aws-…
.github/workflows/marketplace-release.y…:82
HIGH
MINED115
[MINED115] Action `aws-actions/configure-aws-credentials` pinned to mutable ref `@v4`: `u…
.github/workflows/marketplace-release.y…:73
HIGH
MINED115
[MINED115] Action `aws-actions/configure-aws-credentials` pinned to mutable ref `@v4`: `u…
.github/workflows/marketplace-release.y…:67
HIGH
MINED115
[MINED115] Action `tenzir/news/.github/actions/sync` pinned to mutable ref `@main`: `uses…
.github/workflows/sync-news.yaml:25
HIGH
MINED115
[MINED115] Action `actions/create-github-app-token` pinned to mutable ref `@v1`: `uses: a…
.github/workflows/sync-news.yaml:18
HIGH
MINED118
[MINED118] Dockerfile FROM `gcc:15-trixie` not pinned by digest: `FROM gcc:15-trixie` res…
Dockerfile:2
HIGH
MINED118
[MINED118] Dockerfile FROM `public.ecr.aws/docker/library/debian:trixie-slim` not pinned …
Dockerfile:1
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
.github/workflows/nix-build.py:421
MED
CFG006
[CFG006] Missing .gitignore: No .gitignore file. Risk of committing secrets and build art…
—
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
libtenzir/builtins/aggregation-function…:26
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
libtenzir/builtins/aggregation-function…:29
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DKR009
Dockerfile separates apt update from install
Dockerfile:203
MED
DKR009
Dockerfile separates apt update from install
Dockerfile:77
MED
DKR009
Dockerfile separates apt update from install
Dockerfile:67
MED
DKR009
Dockerfile separates apt update from install
Dockerfile:44
MED
DKR001
Docker final stage has no non-root USER
Dockerfile:495
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/to_ftp.cpp:19
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/timeshift.…:160
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/strict.cpp:39
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/sockets.cpp:40
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/sockets.cpp:37
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/serve_tcp.…:45
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/serve_http…:465
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/schemas.cpp:33
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/read_delim…:86
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/processes.…:42
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/plugins.cpp:75
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/partitions…:108
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/parallel.c…:8
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/from_unix_…:89
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/from_tcp.c…:187
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/from_tcp.c…:5
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/from_ftp.c…:240
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/compress_d…:6
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/accept_uni…:133
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/operators/accept_ope…:247
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/functions/time.cpp:99
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/formats/yaml.cpp:334
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/formats/leef.cpp:2
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/contexts/lookup_tabl…:351
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/aggregation-function…:122
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/aggregation-function…:11
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/aggregation-function…:131
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/aggregation-function…:67
LOW
AIC003
Duplicated implementation block across source files
libtenzir/builtins/aggregation-function…:18
LOW
AIC003
Duplicated implementation block across source files
libtenzir/aux/robin-map/include/tsl/rob…:102
LOW
DKR011
Dockerfile installs recommended OS packages
python/Dockerfile:9