-
Notifications
You must be signed in to change notification settings - Fork 1.3k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Set up permissions to github workflow to least privileges (#1718)
Closes #1717 As explained at #1717, github workflow standard behavior grant write-all permissions by default, which can be exploited by an attacker in case of a compromised workflow. To protect the project against this kinds of attacks, it is a Github and OpenSSF Scorecard recommendation to always use the least privilege definition on the workflows.
- Loading branch information
Showing
2 changed files
with
11 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters