Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Harden GitHub actions #77

Merged
merged 1 commit into from
Apr 2, 2024
Merged

Harden GitHub actions #77

merged 1 commit into from
Apr 2, 2024

Conversation

phyrog
Copy link
Collaborator

@phyrog phyrog commented Apr 1, 2024

Describe your changes

Reduce the default permissions of various workflows according to recommendations by the ossf scorecard.

Issue ticket number and link

Checklist before requesting a review

  • I have performed a self-review of my code
  • If it is a core feature, I have added thorough tests.
  • I tested the changes with the following distributions:
    • Kind
    • MiniKube
    • MicroK8s
    • Rancher RKE2
    • Azure AKS
    • GCP GKE (Ubuntu nodes)
    • AWS EKS (AmazonLinux2 nodes)
    • AWS EKS (Ubuntu nodes)
    • Digital Ocean Kubernetes

@phyrog phyrog added security Security related issues area/github_actions Pull requests that update GitHub Actions code kind/feature labels Apr 1, 2024
@voigt voigt merged commit 5f13c4d into main Apr 2, 2024
12 checks passed
@voigt voigt deleted the feat-harden-gh-actions branch April 2, 2024 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/github_actions Pull requests that update GitHub Actions code kind/feature security Security related issues
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants