Skip to content

chore: Set permissions for GitHub actions#3799

Open
naveensrinivasan wants to merge 2 commits intokarma-runner:masterfrom
turrisxyz:Pinned-Dependencies-GitHub
Open

chore: Set permissions for GitHub actions#3799
naveensrinivasan wants to merge 2 commits intokarma-runner:masterfrom
turrisxyz:Pinned-Dependencies-GitHub

Conversation

@naveensrinivasan
Copy link

 Restrict the GitHub token permissions only to the required ones; this way,
 even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

Signed-off-by: naveen <172697+naveensrinivasan@users.noreply.github.com>
@naveensrinivasan naveensrinivasan force-pushed the Pinned-Dependencies-GitHub branch from 69c0d54 to 172f7ae Compare June 24, 2022 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants