Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Set up permissions for GitHub Workflows #216

Open
joycebrum opened this issue Feb 22, 2023 · 0 comments · May be fixed by #217
Open

Set up permissions for GitHub Workflows #216

joycebrum opened this issue Feb 22, 2023 · 0 comments · May be fixed by #217

Comments

@joycebrum
Copy link

joycebrum commented Feb 22, 2023

Hi, I work for Google and the OpenSSF to help open source projects to increase their supply-chain security.

One aspect of supply-chain security checked by the OpenSSF Scorecard and also strongly recommended by the GitHub Security is to always use credentials that are minimally scoped.

Thus, setting top level permissions to contents: read and all write permissions being granted on run level is a simple but important practice regarding GitHub Workflows.

I'll suggest a PR with the permissions changes so let me know if you have any doubts or concerns.

@joycebrum joycebrum linked a pull request Feb 22, 2023 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant