Skip to content

Latest commit

 

History

History
35 lines (27 loc) · 586 Bytes

003.md

File metadata and controls

35 lines (27 loc) · 586 Bytes

deny_write_all_permission

write-all permission should not be used.

Examples

name: test
jobs:
  foo:
    runs-on: ubuntu-latest
    permissions: write-all # Don't use write-all
    steps:
      - run: echo foo

name: test
jobs:
  foo:
    runs-on: ubuntu-latest
    permissions:
      contents: write
    steps:
      - run: echo foo

Why?

For least privilege. You should grant only necessary permissions.