From 3b3b4d3d32410364c1f25b819e6ae09507adc699 Mon Sep 17 00:00:00 2001 From: CRob <69357996+SecurityCRob@users.noreply.github.com> Date: Tue, 21 Jan 2025 11:02:34 -0500 Subject: [PATCH] Update baseline/OSPS-BR.yaml Co-authored-by: Evan Anderson Signed-off-by: CRob <69357996+SecurityCRob@users.noreply.github.com> --- baseline/OSPS-BR.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/baseline/OSPS-BR.yaml b/baseline/OSPS-BR.yaml index cea107c..cdf0b2a 100644 --- a/baseline/OSPS-BR.yaml +++ b/baseline/OSPS-BR.yaml @@ -21,7 +21,7 @@ criteria: to access privileged resources (secret exfiltration, final release, etc.) details: | - Ensure that any build and release pipeline actions + Ensure that any integration or release pipeline actions that accept externally-controlled untrusted input (e.g. git branch names) do not use input in ways that could provide unintended access to privileged resources.