Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Set permissions for GitHub actions #15971

Merged
merged 1 commit into from Jun 11, 2022

Conversation

naveensrinivasan
Copy link
Contributor

 Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
@eslint-github-bot eslint-github-bot bot added triage An ESLint team member will look at this issue soon chore This change is not user-facing labels Jun 7, 2022
@netlify
Copy link

netlify bot commented Jun 7, 2022

Deploy Preview for docs-eslint canceled.

Name Link
🔨 Latest commit 812ce2c
🔍 Latest deploy log https://app.netlify.com/sites/docs-eslint/deploys/629e9bd8fc3458000815389e

@snitin315 snitin315 added evaluating The team will evaluate this issue to decide whether it meets the criteria for inclusion and removed triage An ESLint team member will look at this issue soon labels Jun 10, 2022
Copy link
Member

@nzakas nzakas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks.

@nzakas nzakas merged commit 71bc750 into eslint:main Jun 11, 2022
crapStone pushed a commit to Calciumdibromid/CaBr2 that referenced this pull request Jun 22, 2022
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [eslint](https://eslint.org) ([source](https://github.com/eslint/eslint)) | devDependencies | minor | [`8.17.0` -> `8.18.0`](https://renovatebot.com/diffs/npm/eslint/8.17.0/8.18.0) |

---

### Release Notes

<details>
<summary>eslint/eslint</summary>

### [`v8.18.0`](https://github.com/eslint/eslint/releases/tag/v8.18.0)

[Compare Source](eslint/eslint@v8.17.0...v8.18.0)

#### Features

-   [`a6273b8`](eslint/eslint@a6273b8) feat: account for rule creation time in performance reports ([#&#8203;15982](eslint/eslint#15982)) (Nitin Kumar)

#### Bug Fixes

-   [`f364d47`](eslint/eslint@f364d47) fix: Make no-unused-vars treat for..of loops same as for..in loops ([#&#8203;15868](eslint/eslint#15868)) (Alex Bass)

#### Documentation

-   [`4871047`](eslint/eslint@4871047) docs: Update analytics, canonical URL, ads ([#&#8203;15996](eslint/eslint#15996)) (Nicholas C. Zakas)
-   [`cddad14`](eslint/eslint@cddad14) docs: Add correct/incorrect containers ([#&#8203;15998](eslint/eslint#15998)) (Nicholas C. Zakas)
-   [`b04bc6f`](eslint/eslint@b04bc6f) docs: Add rules meta info to rule pages ([#&#8203;15902](eslint/eslint#15902)) (Nicholas C. Zakas)
-   [`1324f10`](eslint/eslint@1324f10) docs: unify the wording referring to optional exception ([#&#8203;15893](eslint/eslint#15893)) (Abdelrahman Elkady)
-   [`ad54d02`](eslint/eslint@ad54d02) docs: add missing trailing slash to some internal links ([#&#8203;15991](eslint/eslint#15991)) (Milos Djermanovic)
-   [`df7768e`](eslint/eslint@df7768e) docs: Switch to version-relative URLs ([#&#8203;15978](eslint/eslint#15978)) (Nicholas C. Zakas)
-   [`21d6479`](eslint/eslint@21d6479) docs: change some absolute links to relative ([#&#8203;15970](eslint/eslint#15970)) (Milos Djermanovic)
-   [`f31216a`](eslint/eslint@f31216a) docs: Update README team and sponsors (ESLint Jenkins)

#### Build Related

-   [`ed49f15`](eslint/eslint@ed49f15) build: remove unwanted parallel and image-min for dev server ([#&#8203;15986](eslint/eslint#15986)) (Strek)

#### Chores

-   [`f6e2e63`](eslint/eslint@f6e2e63) chore: fix 'replaced by' rule list ([#&#8203;16007](eslint/eslint#16007)) (Milos Djermanovic)
-   [`d94dc84`](eslint/eslint@d94dc84) chore: remove unused deprecation warnings ([#&#8203;15994](eslint/eslint#15994)) (Francesco Trotta)
-   [`cdcf11e`](eslint/eslint@cdcf11e) chore: fix versions link ([#&#8203;15995](eslint/eslint#15995)) (Milos Djermanovic)
-   [`d2a8715`](eslint/eslint@d2a8715) chore: add trailing slash to `pathPrefix` ([#&#8203;15993](eslint/eslint#15993)) (Milos Djermanovic)
-   [`58a1bf0`](eslint/eslint@58a1bf0) chore: tweak URL rewriting for local previews ([#&#8203;15992](eslint/eslint#15992)) (Milos Djermanovic)
-   [`80404d2`](eslint/eslint@80404d2) chore: remove docs deploy workflow ([#&#8203;15984](eslint/eslint#15984)) (Nicholas C. Zakas)
-   [`71bc750`](eslint/eslint@71bc750) chore: Set permissions for GitHub actions ([#&#8203;15971](eslint/eslint#15971)) (Naveen)
-   [`90ff647`](eslint/eslint@90ff647) chore: avoid generating subdirectories for each page on new docs site ([#&#8203;15967](eslint/eslint#15967)) (Milos Djermanovic)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, click this checkbox.

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).

Co-authored-by: cabr2-bot <cabr2.help@gmail.com>
Reviewed-on: https://codeberg.org/Calciumdibromid/CaBr2/pulls/1427
Reviewed-by: Epsilon_02 <epsilon_02@noreply.codeberg.org>
Co-authored-by: Calciumdibromid Bot <cabr2_bot@noreply.codeberg.org>
Co-committed-by: Calciumdibromid Bot <cabr2_bot@noreply.codeberg.org>
@eslint-github-bot eslint-github-bot bot locked and limited conversation to collaborators Dec 9, 2022
@eslint-github-bot eslint-github-bot bot added the archived due to age This issue has been archived; please open a new issue for any further discussion label Dec 9, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
archived due to age This issue has been archived; please open a new issue for any further discussion chore This change is not user-facing evaluating The team will evaluate this issue to decide whether it meets the criteria for inclusion
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants