Skip to content

chore: Set permissions for GitHub actions - #2913

Merged
vitaut merged 1 commit into
fmtlib:masterfrom
turrisxyz:Pinned-Dependencies-GitHub
May 30, 2022
Merged

vitaut merged 1 commit into
fmtlib:masterfrom
turrisxyz:Pinned-Dependencies-GitHub

Conversation

@nathannaveen

Copy link
Copy Markdown
Contributor

 Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: nathannaveen <42319948+nathannaveen@users.noreply.github.com>
@vitaut
vitaut merged commit 11316b2 into fmtlib:master May 30, 2022
@vitaut

vitaut commented May 30, 2022

Copy link
Copy Markdown
Contributor

Thank you

@vitaut

vitaut commented May 31, 2022

Copy link
Copy Markdown
Contributor

BTW is anything preventing a rogue user removing permissions in a PR that will still be run with GitHub Actions?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants