-
-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
There is no timezone Europe/Kyiv #3508
Comments
I'll work to add this. The list in the Dependabot schema was copied from
|
@kurtmckee I was curious what you think about #3519? I added a few entries to the timezone in |
Sorry for the delay in responding. I anticipate that #3519 could severely hinder downstream tools. I see that it's already merged, but I think that most well-designed tools will completely forbid follow-up network access, and will either break outright or will simply stop validating whatever was referenced. Specifications generally allow authors to use referencing syntax, but in the wild it's always an unmitigated disaster for exploits so tools generally turn off network access. See what the XML specification allows versus the list of CVEs against all software that parses XML, for example. As for the immediate effect, I anticipate that tools like check-jsonschema -- which is generally run as pre-commit hooks -- will have to work around these references because pre-commit.ci disallows all network access. |
I see, yeah you were right that #3519 would break many tools. I had to revert it for some of the reasons you mentioned - |
Area with issue?
JSON Schema
✔️ Expected Behavior
I'm trying to create a workflow scenario for the Dependabot using the "Europe/Kyiv" timezone.
Please note that the "Europe/Kyiv" timezone is native to Ukrainians. See the issue here:
dependabot/dependabot-core#6132
❌ Actual Behavior
My IDE (VSCode) shows the red underline and tells me that the timezone is absent in dependabot-2.0.json scheme
YAML or JSON file that does not work.
IDE or code editor.
Visual Studio Code
Are you making a PR for this?
No
The text was updated successfully, but these errors were encountered: