Rules
FP603 · remote-unverified
A job calls a reusable workflow in another repository; its interface is not verified.
| Code | Name | Category | Default severity |
|---|---|---|---|
FP603 | remote-unverified | Graph structure | 🔵 info |
Why it matters
flowpact analyzes this repository only, so inputs, secrets and outputs of the remote workflow are taken on trust.
How to fix
Nothing to fix. If the workflow lives in this repository, set repository: owner/repo in the config so it resolves locally.
Configure
Change the severity (or turn the rule off) in .github/flowpact/flowpact.config.yml, by code or by name:
rules:
FP603: off
# or: remote-unverified: errorExplain it in the terminal:
flowpact explain FP603