Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(github): reduce workflow token permission #928

Merged

Conversation

f4usto
Copy link
Contributor

@f4usto f4usto commented Aug 12, 2024

What does this PR do?

Github token permissions should follow the least privilege principle

Reset workflow permissions to validate we can enable read-only default permissions at repository level to provide a strong baseline protection measure

Motivation

Additional Notes

Possible Drawbacks / Trade-offs

Describe how to test/QA your changes

Reviewer's Checklist

@f4usto f4usto requested a review from a team as a code owner August 12, 2024 10:48
@f4usto f4usto merged commit 6306f4b into main Aug 12, 2024
13 checks passed
@f4usto f4usto deleted the f4usto/set-least-permissions-to-github-token-on-workflows branch August 12, 2024 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants