Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: define permissions for enforce-labels workflow #760

Merged
merged 1 commit into from
May 9, 2024

Conversation

fgreinacher
Copy link
Contributor

@fgreinacher fgreinacher commented May 6, 2024

Explicitely stating required permissions is considered best practice.
This case was detected by Poutine, see
https://github.com/boostsecurityio/poutine/blob/main/docs/content/en/rules/default_permissions_on_risky_events.md.

⚒️ with ❤️ by Siemens

Explicitely stating required permissions is considered best practice.
This case was detected by Poutine, see
https://github.com/boostsecurityio/poutine/blob/main/docs/content/en/rules/default_permissions_on_risky_events.md.

Signed-off-by: Florian Greinacher <florian@greinacher.de>
@fgreinacher fgreinacher marked this pull request as ready for review May 6, 2024 06:40
@schurzi
Copy link
Contributor

schurzi commented May 9, 2024

nice addition, thank you @fgreinacher!

@schurzi schurzi merged commit 4f66ec4 into dev-sec:master May 9, 2024
6 checks passed
@fgreinacher fgreinacher deleted the ci/permissions branch May 9, 2024 15:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants