Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restrict token permissions for Auto Assign PR #61

Closed
irongut opened this issue Aug 5, 2022 · 2 comments
Closed

Restrict token permissions for Auto Assign PR #61

irongut opened this issue Aug 5, 2022 · 2 comments
Assignees
Labels
DevOps enhancement New feature or request Security Security vulnerabilities or improvements stale

Comments

@irongut
Copy link
Owner

irongut commented Aug 5, 2022

Feature Request

The Auto Assign PR workflow doesn't have GitHub token permissions specified because it uses an Action not in the StepSecurity database.

Expected Behaviour

All workflows should restrict the GitHub token permissions.

Additional Context

Linked To

#49 Implement StepSecurity Secure Workflows (audit)
#51 Implement StepSecurity Secure Workflows (policy)

@irongut irongut added enhancement New feature or request DevOps Security Security vulnerabilities or improvements labels Aug 5, 2022
@irongut irongut self-assigned this Aug 5, 2022
@irongut irongut pinned this issue Aug 5, 2022
@github-actions
Copy link

github-actions bot commented Nov 4, 2022

This issue is stale because it has been open 90 days with no activity. Remove stale label or comment or this issue will be closed in 30 days.

@github-actions github-actions bot added the stale label Nov 4, 2022
@github-actions
Copy link

github-actions bot commented Dec 5, 2022

This issue was closed because it has been stale for 30 days with no activity.

@github-actions github-actions bot closed this as completed Dec 5, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
DevOps enhancement New feature or request Security Security vulnerabilities or improvements stale
Projects
None yet
Development

No branches or pull requests

1 participant