Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Securing permissions - AppSec Pod #959 #973

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

Securing permissions - AppSec Pod #959 #973

wants to merge 2 commits into from

Conversation

andrewalson
Copy link

  • Reduced permissions for statuses, checks, security-events, and deployments to read/write where necessary (small reduction of attack).
  • Restricted permissions for contents, packages, and actions to lower risk (large reduction of attack).
  • Improved overall security posture by minimizing potential access to sensitive operations.

Implemented all suggestions for maximum reduction of attack. Alongside additions, changes to the existing permissions block include actions to none from read, while values for contents and security-events are unchanged.

Previous permissions block:

permissions:
  actions: read
  contents: read
  security-events: write

Copy link

emote

Copy link

Hello there, thanks for opening your first Pull Request. Someone will review it soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants