gitea actions: update / clarify maintenance on them or can we just use github actions instead ? #29406
Labels
issue/needs-feedback
For bugs, we need more details. For features, the feature must be described in more detail
type/proposal
The new feature has not been accepted yet but needs to be discussed first.
Uh oh!
There was an error while loading. Please reload this page.
gitea actions update clarification
Hi,
not sure whether this is a good feature request but will try anyway (it is more of a proposal).
problem / context:
gitea.com uses github compatible actions fot pipelines. but some / most of the actions offered on gitea.com are outdated and contain vulnerabilities.
example: see below trivy scanning reports on the actions/checkout repo.
i think pulling in some software as part of running a pipeline is ok as long as there is trust on that the code is maintained / safe.
questions:
from what i see each gitea actions repo is a plain mirror of github, but simply not updated ?
suggestions:
can you share some light on whether it's recommeneded to use github actions straight away or share wether there is intention to update the gitea actions ?
or it's perhaps to early to tell (since gitea actions are still work in progress?
other than that: documentation looks great, speed of gitea is excellent so thanks already for that.
Screenshots
The text was updated successfully, but these errors were encountered: