Skip to content

Latest commit

 

History

History
35 lines (27 loc) · 581 Bytes

002.md

File metadata and controls

35 lines (27 loc) · 581 Bytes

deny_read_all_permission

read-all permission should not be used.

Examples

name: test
jobs:
  foo:
    runs-on: ubuntu-latest
    permissions: read-all # Don't use read-all
    steps:
      - run: echo foo

name: test
jobs:
  foo:
    runs-on: ubuntu-latest
    permissions:
      contents: read
    steps:
      - run: echo foo

Why?

For least privilege. You should grant only necessary permissions.